how to find which process had created any file in Linux
9,171
Solution 1
If you don't have any process that monitors these changes/creations than you have no way to know which process actually created a file or did anything.
This link may help you start with files auditing : Linux audit files to see who made changes to a file
In case you are a programmer you may be interested in "Monitor Linux file system events with inotify"
Solution 2
No. You can only monitor future file creation by using the auditing subsystem.
Author by
P7oKhom
Updated on September 18, 2022Comments
-
P7oKhom over 1 year
Is there any way to know which process had created any file in Linux Red Hat/CentOS 5?
-
Raghavendra B N over 2 yearsThere's a good answer to this question on the Linux StackExchange: unix.stackexchange.com/a/13791/10822
-
-
user1686 about 13 years
inotify
doesn't give the process ID; you would need to usefanotify
for that.