The Linux file integrity monitor detects file modifications on Linux devices. This acts as a security control that raises alerts by monitoring modifications and preventing unauthorized changes.
The main purpose of the Linux file integrity check is to detect any unauthorized file modifications and to send timely alerts for any modification. A Linux file integrity check can be added using Setup > Monitoring > Templates > Other Monitors.
Create Linux file integrity check monitors
Select a client from the All Clients list.
Go to Setup > Monitoring > Templates.
From TEMPLATES, click +Add, which displays the MONITOR TEMPLATE screen.
From MONITOR TEMPLATE, enter:
Select Template Scope: The partner template or client-specific template. For the client-specific template, select the client.
Collector Type: The application type used to gather information. Select the agent.
Applicable for: The type of the application.
Template Name: The name of the template.
Description: The summary of the template.
Generation: The generation that the template belongs to. For example, Generation 2.
Tags: The user-defined tags used for enhanced filtering.
Prerequisites: The essential prerequisites to consider while monitoring using a template.
Status: The active or end-of-life templates.
Notes: Additional information to add to the template.
Template Family Name: The category that applies to the application.
Deployment Type: Select one of the following methods to apply the template to resources:
After entering the template details, go to Other Monitors and click +Add.
From the options displayed in Monitor Type drop-down, select Linux File Integrity Check.
From Linux File Integrity Check, to enter more detailed parameters, click Add and Remove to increase or decrease following settings:
- Frequency: The intervals used to monitor the files. The recommendation is 15 minutes.
- Alert: Select Alert to receive alerts for any match.
- Priority: The priority of the alert.
- Name: The unique identifier for the file.
- File Name: The absolute path of the file.
After adding a template with Linux file integrity check, assign the template to a device to start monitoring.
Manage Linux file integrity checks
Linux file integrity check monitor details can be viewed and modified when added to a template. Perform the following actions to manage the file integrity monitor:
- Edit: Click the template name displayed on the templates screen to modify the monitor details.
- View: View the monitor details in the templates screen. Click the arrow next to the template name to view the Linux file integrity monitor added to the current template.
Linux file integrity check alerts
OK alerts are sent while monitoring the files. View the alerts in the Alert browser. Examine the alert description to verify the last modified time.