On Wed, 2007-05-30 at 14:06 -0400, Steve Grubb wrote: > While that does tell you the file system type, the audit rule comparitor does > not use that field to trigger an event. Maybe that would be something useful > to add to the comparitor?
Actually I would be matching on this in an external system. That system would receive *all* open() calls. It just needs to be able to differentiate nfs from non-nfs. > Matthew, what kernel are you using? It's RHEL 4, x86_64. Matt -- Matthew Booth, RHCA, RHCSS Red Hat, Global Professional Services M: +44 (0)7977 267231 GPG ID: D33C3490 GPG FPR: 3733 612D 2D05 5458 8A8A 1600 3441 EA19 D33C 3490
signature.asc
Description: This is a digitally signed message part
-- Linux-audit mailing list [email protected] https://www.redhat.com/mailman/listinfo/linux-audit
