selinux audit rule not logging anything
Solution 1:
The man page says that -w
is deprecated, so I wouldn't be using it. I'd be using the current format for such a rule instead. For example:
auditctl -a always,exit -F dir=/path/to/dir/ -k media-watch