[Aide] Rules to exclude all files except one

Hannes von Haugwitz hannes at vonhaugwitz.com
Thu Nov 19 21:08:15 EET 2015


Hi,

On Wed, Nov 18, 2015 at 06:23:23PM +0100, Brian Mathis wrote:
> I'm trying to setup some rules that exclude all files/dirs in a
> subdirectory except for one, without itemizing every file to exclude.
> 
> Example:
>     /opt/app/dir1    --> exclude
>     /opt/app/dir2    --> include
>     /opt/app/dir3    --> exclude
> 
> I'm trying something like this, but can't seem to get it working:
>     /opt/app/dir2/.*    NORMAL
>     !/opt/app/
>     /    EVERYTHING
> The ! rule always seems to override the dir2 rule.
> 
> Is there any way to accomplish this with aide?

I'm pretty sure that this is not possible with the current version of
AIDE.

Currently I'm working on the rule handling of AIDE and I'll keep your
use case in mind. Perhaps there is a simple solution to fix this
issue.

Best regards

Hannes


More information about the Aide mailing list