I'm noticing exactly the same problem mentioned into this old message
http://osdir.com/ml/linux.redhat.security.audit/2006-07/msg00036.html
Workaround consisting into watching the whole directory containing the file
works too. I've found that into 2006 a patch was submitted to solve the
issue
http://www.mail-archive.com/linux-audit@redhat.com/msg00476.html
Is this a recent regression, or is there something I don't know?
Arch Linux
audit 2.1.1
kernel 2.6.38.7
i686 architecture
Thanks in advance