• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
NameHero® Blog

NameHero® Blog

Web Hosting Tips & Resources From NameHero

  • AI Agents
    • OpenClaw
    • Claude Code
    • n8n
    • Hermes Agent
    • Open WebUI
    • Docker
  • Hosting
    • Web Hosting
    • WordPress Hosting
    • WooCommerce Hosting
    • Enterprise Hosting
    • Email Hosting
    • HeroicGuard
    • GPU Hosting
    • Website Builder
  • VPS
    • Managed VPS
    • Unmanaged VPS
    • Flex VPS
  • Reseller
  • Gaming
  • Domains
  • Account
  • Blog Home
  • Categories
  • Authors

Getting Started with Auditctl On Linux

CJ Saathoff

Published on: August 8, 2024

Categories: Linux Command Line 0

Have you ever needed to monitor a file for changes? Has a file been changing but you don’t know why? If you answered yes to either of those questions, the auditctl is the command you have been looking for. In this blog post, we will explore the basics of how to utilize auditctl to track down changes to files when the cause is unknown.

Table of Contents
  • Introduction
  • Installation
    • Start and Enable
    • Note On Configuration
  • Setting Up Rules
    • Examples
    • Persistent Rules
  • Checking For Rules
  • Checking The Results
  • Deleting Existing Rules
    • Removing A Persistent Rule
  • Conclusion
  • Additional Links

Introduction

The auditctl command is a command line utility used to configure Linux kernel options related to auditing. Auditctl is part of auditd which contains more related pieces. In this post, we will focus on getting set up, adding rules for monitoring files and directories, checking the loaded rules, looking at the results, and deleting rules. Be aware this requires sudo access or access to the root user.

Installation

To install the audit system the package will be audit or auditd in most package managers.

For Debian/Ubuntu

sudo apt install auditd

For most RPM-based systems

sudo apt install audit

Start and Enable

Once installed make sure to start and enable the service using service or systemctl (depending on what the system uses).

Init.d

sudo service auditd start
sudo service auditd enable

Systemd

sudo systemctl start auditd
sudo systemctl enable auditd

Note On Configuration

The audit configuration file is typically located at /etc/audit/auditd.conf.

Though for what we will be covering there is no need to make any configuration file changes.

Setting Up Rules

To set up a rule the syntax will be as follows:

sudo auditctl -w [file_name] -p [permissions] -k [name]
  • [file_name] – is the full file path to the file you want to watch for changes on.
  • [permissions] – This is what changes you want to watch for on the file.
    • r – The r flag specifies you want to log anything reading the file.
    • w – The w flag specifies you want to log anything writing to the file.
    • x – The x flag specifies you want to watch for the file being run.
    • a – The a flag specifies you want to watch for attribute changes.

Be aware that rules added this way are not persistent persist across reboots.

Examples

Here are a few examples once we put everything together:

sudo auditctl -w /etc/exim.conf -p wa -k exim-config

The above command is watching write and attribute changes.

sudo auditctl -w /etc/shadow -p rw -k user-accounts

The command above will watch /etc/shadow for read and write.

sudo auditctl -w /usr/bin -p x -k dir-watch

This will watch for files being executed within the directory /usr/bin.

Persistent Rules

To apply rules across reboots enter the rules in /etc/audit/rules.d/audit.rules or another .rules file in /etc/audit/rules.d/

To add the rule remove anything before and up to auditctl, meaning your rule should start with -w.

Using one of the above examples this is what you would /append to the file:

-w /usr/bin -p x -k dir-watch

Make sure to save and exit the file.

Then reload the rules.

sudo systemctl reload auditd

Checking For Rules

To see which rules are loaded aka the rule list run the following command:

auditctl -l

The results will show one of two things, either “No rules” indicating there are no rules set, or the rules that are currently in place.

Checking The Results

The two simplest ways to check the audit records are to filter on the watch name or the file both are shown below.

ausearch -k [name]
ausearch -f [file]

Deleting Existing Rules

To Delete an existing rule change the first -w to a capital -W.

Like so:

-W /usr/bin -p x -k dir-watch

Removing A Persistent Rule

To remove the rule, the entry from the associated file in /etc/audit/rules.d/.

Make sure to save and exit the file.

Then reload the rules.

sudo systemctl reload auditd

Conclusion

Auditd is the answer to “This file has been changing but I don’t know why”. In this blog post, we will explore the basics of how to utilize auditctl to track down changes to files when the cause is unknown. From getting things set up, setting up rules for monitoring files and directories, checking loaded rules, checking the results, and deleting rules.

Additional Links

Done reading and looking for additional links, why not check these out?

  • cPanel Audit System
  • Arch Wiki Audit Framework
CJ Saathoff

Embracing a lifelong passion for technology since childhood, CJ delved into the intricate workings of systems, captivated by the desire to understand the unknown. This innate curiosity led to his discovery of Linux, a revelation that resonated deeply. With more than 7 years of on the job experience, he’s honed his technical skills as a Geek and Senior Linux Systems Administrator.

Related Posts

Bash Conditional Expressions: [[ vs [ vs test

In bash scripts, we use conditional statements frequently. Whether it’s in an “if fi” logic block or within a “while” or “do” loop, we evaluate statements all the time to determine whether they’re true or false, and perform various actions based on the result. True to form, there are multiple ways to do this, and […]

How to Tar and Gzip a Folder

Here's how to archive and compress a folder so that it's easy to move it from one location to another - In both Linux AND Windows!

Bash Signal Handling with Trap: EXIT, ERR, INT

Bash in Linux allows us to set functions that run when certain signals are generated - either by the script, or the shell. Here's how.

Systemd Service File Example – How it Works

The service file manager in Linux - systemd - is configured using something called "unit files". Here's an example, and how it works.

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Primary Sidebar

Follow & Subscribe

Exclusive promos, content and more!


Most Popular Posts

NameHero’s Recommended WordPress Plugin and Theme Setup

WordPress Hosting vs. Web Hosting – What’s The Difference?

How To Increase The InnoDB Buffer Pool Size

How To Fix A Stuck All-in-One WP Migration Import

How To Add A Subdomain In Cloudflare

Top Categories

  • WordPress
  • WordPress Tutorials
  • OpenClaw Hosting
  • Enterprise Hosting
  • WooCommerce
  • Web Hosting
  • Resellers
  • Website Security
  • Website Development
  • Website Performance
  • VPS Hosting
  • SEO Tips
  • Announcements
  • Domain Registration
NameHero

NameHero® proudly provides web hosting to over 40,000 customers with 99.9% uptime to over 750,000 websites.

  • Master Card
  • Visa
  • American Express
  • Discover
  • Paypal
Products
  • Web Hosting
  • Managed VPS Hosting
  • Unmanaged VPS Hosting
  • Flex VPS Hosting
  • WordPress Hosting
  • WooCommerce Hosting
  • Reseller Hosting
  • Enterprise Hosting
  • GPU Hosting
  • Email Hosting
  • HeroicGuard
  • Domains
  • Website Builder
  • AI Agent Hosting
Help & Support
  • NameHero Blog
  • NameHero Gaming Blog
  • Support
  • Help Center
  • Migrations
  • Affiliates
  • Gaming Affiliates
  • Call 1-855-984-6263
Company
  • About Us
  • Contact Sales
  • Reviews
  • Uptime
  • We're Hiring

Copyright © 2026 Name Hero, LLC. All rights reserved.
NameHero® is a registered trademark.

  • Privacy Policy
  • Terms of Use
  • Acceptable Use Policy
  • Payment Policy
  • DMCA