Home Artica & System System Monitoring audit files to see who/what made changes to a directory

audit files to see who/what made changes to a directory

Print PDF

This feature is available with artica version 1.4.092819

If you are under this release you need to upgrade your Artica version.
If this version is not released use the How to upgrade Artica to a nightly build ?

this feature use auditd daemon that can be installed by

apt-get install auditd
yum install audit

It run a watchdog from specified directories and store events into mysql database.

With this feature you can follow an history with all files exchanges. useful to see who or what are deleted or read a file.

  • Click on Explorer on the top menu
  • browse your disk and select the directory you want to audit.
  • On the left pan of the directory informations, click on the magnifying glass icon

 

Turn the red circle to green in order to activate the watchdog feature on the directory.

 

After severals minutes you can view the events trough Artica Interface.

  • On the left menu, click on events/Auditd daemon.
  • On the right pan, select the folder icon on the desired directory.

You can search/Find/select events to display specific operations made on a file or a group file.