Has anyone successfully been able to add a filesystem watch list to the audit system? I added the -w /var/log to the audit.rules file as -w /var/log and when I show the rules, it complains about a configuration error on that line. All help is appreciated. Dave - : send the line "unsubscribe linux-admin" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html