Hello,
I am trying to exclude a directory and all of its sub-directories and contents from being audited.
I generated this syntax :
-a never,exclude -F path=/root/test
However, I am still getting audits from scripts generating files within this path.
Can you suggest a proper configuration for excluding a directory along with its sub-directories and contents.
We are on RHEL 6.9 and currently our audit version is : audit-2.4.5-3.el6.x86_64
Thanks for your support!
George Sarker.