|
David
|
posted 4/4/07 1:09 PM
I suggest doing it on two levels. First, as an os admin, monitor all root filesystems initially. As you see things that are reported you do not care to see, exclude them. The second level is to do it on an app level. You want to monitor the app fs so that if hackers or developers change things, you can see the changes. What you monitor on the app level might be different though depending on whether it is a development box or production box.
|