0
1
I setup daily cron job checking if files have changed previous day, since those files are not suppose to changed i'm getting empty report, how can i change it to send email prevent this.
this is my cron job line
1 0 * * * root /sbin/aureport -k -ts yesterday 00:00:00 -te yesterday 23:59:59
and this is an email i'm usually getting
Key Report
===============================================
# date time key success exe auid event
===============================================
<no events of interest were found>
yes but /var/log/audit/audit.log file constantly changes with some entries that aren't relevant to that aureport that checks just for particular, i'm wondering if we could run, first capture its output and check if the output contains <no events of intrest were found> string and if so, then print it ? – user398140 – 2015-01-14T09:53:00.127
@user398140 amended answer based on your feedback comment – Antony – 2015-01-14T10:41:24.333