Код: Выделить всё
[global]
log level = 1 vfs:1
syslog = 0
full_audit:prefix = %u|%I
full_audit:success = connect, open, mkdir, rmdir, unlink, write, rename
full_audit:failure = none
vfs objects = full_audit
Код: Выделить всё
Dec 4 00:03:20 server smbd_audit: nobody|192.168.x.x|open|ok|r|desktop.ini
Dec 4 00:10:50 server smbd_audit: nobody|192.168.x.x|open|ok|r|desktop.ini
Dec 4 00:10:59 server smbd_audit: nobody|192.168.x.x|connect|ok|public
Dec 4 00:10:59 server smbd_audit: nobody|192.168.x.x|open|ok|r|desktop.ini
Dec 4 00:10:59 server smbd_audit: nobody|192.168.x.x|connect|ok|public
Dec 4 00:11:26 server smbd_audit: nobody|192.168.x.x|open|ok|r|desktop.ini
Dec 4 00:12:13 server smbd_audit: nobody|192.168.x.x|connect|ok|public
Dec 4 00:12:20 server smbd_audit: nobody|192.168.x.x|open|ok|r|desktop.ini
Dec 4 00:15:25 server smbd_audit: nobody|192.168.x.x|open|ok|r|desktop.ini
Dec 4 00:17:19 server smbd_audit: nobody|192.168.x.x|connect|ok|public
Dec 4 00:17:40 server smbd_audit: nobody|192.168.x.x|connect|ok|public
Dec 4 00:17:40 server smbd_audit: nobody|192.168.x.x|open|ok|r|desktop.ini
Dec 4 00:17:42 server smbd_audit: nobody|192.168.x.x|open|ok|r|realizacia
Dec 4 00:22:20 server smbd_audit: nobody|192.168.x.x|open|ok|r|desktop.ini
...
...
...
Dec 4 18:13:46 server smbd_audit: nobody|192.168.x.x|unlink|ok|Red_birzha/Борматова Е С/~WRL1651.tmp
Dec 4 18:13:46 server smbd_audit: nobody|192.168.x.x|open|ok|r|Red_birzha/Борматова Е С/~$ановости.doc
Dec 4 18:13:46 server smbd_audit: nobody|192.168.x.x|open|ok|r|Red_birzha/Борматова Е С/~$ановости.doc
Dec 4 18:13:46 server smbd_audit: nobody|192.168.x.x|open|ok|w|Red_birzha/Борматова Е С/~$ановости.doc
Dec 4 18:13:46 server smbd_audit: nobody|192.168.x.x|open|ok|r|Red_birzha/Борматова Е С/~$ановости.doc
Dec 4 18:13:46 server smbd_audit: nobody|192.168.x.x|unlink|ok|Red_birzha/Борматова Е С/~$ановости.doc
Dec 4 18:14:52 server smbd_audit: nobody|192.168.x.x|open|ok|r|Red_birzha/Борматова Е С/Ааановости.doc
Dec 4 18:28:17 server smbd_audit: nobody|192.168.x.x|open|ok|w|Red_birzha/Борматова Е С/Ааановости.doc
Dec 4 18:28:17 server smbd_audit: nobody|192.168.x.x|open|ok|w|Red_birzha/Борматова Е С/~$ановости.doc
Dec 4 18:32:11 server smbd_audit: nobody|192.168.x.x|open|ok|r|Red_birzha/Борматова Е С/~$ановости.doc
Dec 4 18:49:18 server smbd_audit: nobody|192.168.x.x|open|ok|r|Red_birzha/Борматова Е С/~WRL0174.tmp
Dec 4 18:49:18 server smbd_audit: nobody|192.168.x.x|open|ok|w|Red_birzha/Борматова Е С/~WRL0174.tmp
Dec 4 18:49:18 server smbd_audit: nobody|192.168.x.x|open|ok|r|Red_birzha/Борматова Е С/~WRL0174.tmp
Dec 4 18:49:18 server smbd_audit: nobody|192.168.x.x|unlink|ok|Red_birzha/Борматова Е С/~WRL0174.tmp
Вопрос: Можно какое-нибудь исключение сделать? Это мне нафиг не нужно. Из 2-х полезных строк - 10 ненужных
