The Linux file integrity monitor detects file changes on Linux devices. This acts as a security control that raises alerts by monitoring changes and preventing unauthorized changes.

The main purpose of the Linux file integrity check is to detect any unauthorized file changes and to send timely alerts. A Linux file integrity check can be added using Setup > Monitoring > Templates > Other Monitors.

Create Linux file integrity check monitors

  1. Select a client from the All Clients list.

  2. Go to Setup > Monitoring > Templates.

  3. From TEMPLATES, click +Add, which displays the MONITOR TEMPLATE screen.

  4. From MONITOR TEMPLATE, enter:

    • Select Template Scope: The partner template or client-specific template. For the client-specific template, select the client.

    • Collector Type: The application type used to gather information. Select the agent.

    • Applicable for: The type of the application.

    • Template Name: The name of the template.

    • Description: The summary of the template.

    • Generation: The generation that the template belongs to. For example, Generation 2.

    • Tags: The user-defined tags used for enhanced filtering.

    • Prerequisites: The essential prerequisites to consider while monitoring using a template.

    • Status: The active or end-of-life templates.

    • Notes: Additional information to add to the template.

    • Template Family Name: The category that applies to the application.

    • Deployment Type: Select one of the following methods to apply the template to resources:

      • Custom
      • Optional
      • Standard
  5. Click Save.

  6. After entering the template details, go to Other Monitors and click +Add.

  7. From the options displayed in Monitor Type drop-down, select Linux File Integrity Check.

  8. From Linux File Integrity Check, to enter more detailed parameters, click Add and Remove to increase or decrease following settings:

    • Frequency: The intervals used to monitor the files. The recommendation is 15 minutes.
    • Alert: Select Alert to get alerts for any match.
    • Name: The unique identifier for the file.
    • File Name: The absolute path of the file.
    Add Linux File Integrity Check Monitor

After adding a template with Linux file integrity check, assign the template to a device to start monitoring.

Manage Linux file integrity checks

Linux file integrity check monitor details can be viewed and modified when added to a template. Do the following actions to manage the file integrity monitor:

  • Edit: Click the template name displayed on the templates screen to change the monitor details.
  • View: View the monitor details in the templates screen. Click the arrow next to the template name to view the Linux file integrity monitor added to the current template.
Manage Linux File Integrity Check Monitor

Linux file integrity check alerts

Critical and OK alerts are sent while monitoring the files. View the alerts in the Alert browser. Examine the alert description to verify the last modified time.

Linux File Integrity Check Alerts