# File Integrity Control

**URL:** <https://forums.suse.com/t/file-integrity-control/34663>\
**Category:** SLES Configure-Administer\
**Created:** [December 22, 2019, 3:26pm UTC](https://forums.suse.com/t/file-integrity-control/34663 "2019-12-22T15:26:53Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![LuckyNumber17](https://avatars.discourse-cdn.com/v4/letter/l/a6a055/32.png) [@LuckyNumber17](https://forums.suse.com/u/LuckyNumber17)\
**Post date:** [December 22, 2019, 3:26pm UTC](https://forums.suse.com/t/file-integrity-control/34663/1 "2019-12-22T15:26:53Z")

</div>

Greetings!  
I want the audit system to log activities with files in certain directories (like /etc or /bin) into separate logfile. For example, if a configuration file was modified inside a directory under control, I would be able to see changes made to it in a special log.  
How to create such configuration?

Also, I add watches on directories by adding rules like

```auto
-w /etc
```

But still, audit.log does not contain the facts of changing and creating files in /etc directory. What am I missing? Also, the log doesn’t contain timestamps - how to enable them so it would be clear when something happened

With best regards,  
Max
