You can use auditd and add a rule for that file to be watched:
auditctl -w /path/to/that/file -p wa
Then watch for entries to be written to /var/log/audit/audit.log.
You can use auditd and add a rule for that file to be watched:
auditctl -w /path/to/that/file -p wa
Then watch for entries to be written to /var/log/audit/audit.log.
转载于:https://www.cnblogs.com/zhangdewang/p/10307365.html