selinux audit rule not logging anything

Solution 1:

The man page says that -w is deprecated, so I wouldn't be using it. I'd be using the current format for such a rule instead. For example:

auditctl -a always,exit -F dir=/path/to/dir/ -k media-watch