Real-time System Integrity Monitoring

System Integrity Monitoring detects each change to an object within the monitoring scope by intercepting file operations in real time.

When System Integrity Monitoring runs, the application monitors changes in the following file settings:

A file checksum is not calculated.

The technical limitations of the Linux operating system prevent the application from identifying the user or process that made the changes to the file.

System Integrity Monitoring is disabled by default. You can enable, disable, and configure System Integrity Monitoring:

When a directory is added to a monitoring or exclusion scope, the application does not check whether that directory exists.

In this section

Configuring System Integrity Monitoring in the Web Console

Configuring System Integrity Monitoring in the Administration Console

Configuring System Integrity Monitoring in the command line

Page top