Find the answer to your Linux question:
Results 1 to 5 of 5
Enjoy an ad free experience by logging in. Not a member yet? Register.
  1. #1

    Post Monitoring Directories and Files

    Hi guys

    A question has been put to me from my university and I'm lost as to where to begin, hopefully you can help.

    In learning and understanding Linux which Directories and Files could you monitor for changes. I have a fair understanding of how Inotify works, the problem is the vagueness of the question. The question only asks which directories and files could you consider monitoring

    Any help you can give me would be great


  2. #2
    Trusted Penguin Irithori's Avatar
    Join Date
    May 2009
    That question is vague and from my pov it depends on the scenario.
    In a (very) high security environment: probably all files.
    For filesync setup between multiple servers? The datadirectory(s) to be synced.
    In general I would say it doesnt make too much sense to monitor volatile files like /proc /dev etc and logfiles in /var/log for change. Because.. they do

    You might want to check /bin, /sbin, /usr/bin, /usr/sbin as they should only change in a controlled way: aka via update or install of packages.
    But then again, I wouldnt use inotify here. Wrong tool: waste of ressources, and there are more sophisticated ones like tripwire, aide, etc

    I guess this question is meant to make you think in a braindump way,
    and does not expect a specific answer.
    Because that would need a specific scenario, imho.
    You must always face the curtain with a bow.

  3. #3
    Thanks for your reply, I was on another forum and they were giving me such plain answers. Very precise, thanks a lot

  4. $spacer_open
  5. #4
    Linux Enthusiast
    Join Date
    Aug 2006
    Portsmouth, UK
    You might also be interested in "inotify" if it's available for your distribution.
    inotify - Wikipedia, the free encyclopedia

    It first appeared in RHEL / CentOS 5 if your a RedHat type...
    RHCE #100-015-395
    Please don't PM me with questions as no reply may offend, that's what the forums are for.

  6. #5
    Linux Guru Rubberman's Avatar
    Join Date
    Apr 2009
    I can be found either 40 miles west of Chicago, in Chicago, or in a galaxy far, far away.
    The inotify tools are also available for Debian-based distributions. I have used it on ARM9 processor-based systems as well as on CentOS/RHEL and Ubuntu. It should be available on just about any 2.6 kernel system.
    Sometimes, real fast is almost as good as real time.
    Just remember, Semper Gumbi - always be flexible!

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts