Hi guys,
I'm looking for a way to record events when an user tries to access or execute a command/file that he doesn't have permissions to.
So far, it seems like auditd is the way to go but I just can't get the configuration right. I've tried using ex,pc and na classes but the logs are full of noise and doesn't have the information I'm interested in (the permission denied events).
Any pointers with this would be great!
thanks,
Amit
I'm looking for a way to record events when an user tries to access or execute a command/file that he doesn't have permissions to.
So far, it seems like auditd is the way to go but I just can't get the configuration right. I've tried using ex,pc and na classes but the logs are full of noise and doesn't have the information I'm interested in (the permission denied events).
Any pointers with this would be great!
thanks,
Amit