1

Audit rules setup and filtering command execution

view story
linux-howto

http://www.linuxquestions.org – Hi Friends, I have a RHEL 5.8 server running Oracle RAC, In audit.rules file I have rule setup to monitor permission changes and file deletion. There are multiple entries in the file for oracle services (comm=ohasd.bin). which I want to filter out. Could you please advise how can I filter all events generated for ohasd.bin. so that they are not reported in the audit.log Thanks. (HowTos)