wget https://mirrors.aliyun.com/epel/7/x86_64/Packages/i/inotify-tools-3.14-9.el7.x86_64.rpm
sudo rpm -ivh inotify-tools-3.14-9.el7.x86_64.rpm
inotifywait -m -r -e modify,move,create,move_self /home/tlbb/Server/Log
输出案例:
[root@centos opt]# inotifywait -m -r -e modify,move,create,move_self /home/tlbb/Server/Log
Setting up watches. Beware: since -r was given, this may take a while!
Watches established.
/home/tlbb/Server/Log/ MOVE_SELF
/home/tlbb/Server/Log/ MOVE_SELF
方法二:
直接监控rename系统调用
sudo auditctl -a always,exit -F arch=b64 -S rename,renameat,renameat2 -F dir=/home/tlbb/Server/Log -k dir_rename
sudo ausearch -k dir_rename -i
|