Bookmark this page

Summary

In this chapter, you learned:

  • AIDE allows you to detect changes made to a machine's file systems.

  • An AIDE check can be run manually or by scheduling it with a tool such as crontab, and detect changes using a database of baseline information.

  • You use the /etc/aide.conf file to configure checks that AIDE performs against specific files and directories using group definitions, selection lines, and macros.

  • You need to rebuild the AIDE database file to accept authorized changes to files and to apply new settings from the configuration file.

  • You can use Audit in conjunction with AIDE to help you determine what process or user caused a change that AIDE is reporting.

Revision: rh415-7.5-b847083