So, I'm looking to audit file access (via syscalls
create,open,unlink,etc. because I want every file in the filesystem and
do not want to have to specify an audit rule for each dir/file) that are
accessed via nfs from the nfs server. It seems, I assume because nfs is
in the kernel, that I am not getting any audit messages for those nfs
files access.
Is my assumption correct?
Any suggestions for auditing from the nfs server side?
BTW: not a list subscriber, please reply directly.
Thanks
Bob
--
Bob Kryger Office: 212-813-8677
Systems/Network Administrator Cell: 917-913-6670
SAC Capital, Synapse Group email: bobk(a)sac.com
540 Madison Ave AIM: sacbobk
New York, NY 10022
DISCLAIMER: This e-mail message and any attachments are intended solely for the use of the
individual or entity to which it is addressed and may contain information that is
confidential or legally privileged. If you are not the intended recipient, you are hereby
notified that any dissemination, distribution, copying or other use of this message or its
attachments is strictly prohibited. If you have received this message in error, please
notify the sender immediately and permanently delete this message and any attachments.