Is implementing real time monitoring using kevent() on FreeBSD (and MAC
os X) in the pipeline? Otherwise is someone already working on this? If
not, I'll try to get this done on a rainy day.
Any info, advise would be greatly appreciated.
-Linux's inotify():
http://www.ibm.com/developerworks/linux/library/l-ubuntu-inotify/
-FreeBSD's kevent(): http://benno.id.au/blog/2008/05/15/simplefilemon
-OSSEC file to adapt:
https://bitbucket.org/dcid/ossec-hids/src/326e8d3d1d72/src/syscheckd/run_realtime.c
regards,
--
Danny Fullerton, CISSP GCIH GHTQ
Founder
Mantor Organization
B5E4 ADB4 AD81 A69A E5DB A475 91C9 E6AF 1948 8708
Thanks,