Follow file activity
Build audit logs around create, delete, modify, and open events. Inspect file identity and name records from the kernel.
Explore the audit loggerA Ruby gem for Linux
Listen in Ruby. Watch file activity and respond to permission events with native Linux fanotify bindings.
Ruby 3.2+ Linux 5.1+ MIT licensed
/datareport.csvcreatednotes.txtmodifiedevent.mask # => [:create]
event.name # => "report.csv"
Install the gem, choose a directory, and handle the events you care about. Start with ordinary notifications.
gem install fanotifyBuilds a native extension. You’ll need a C compiler and Linux UAPI headers.
View on RubyGemsrequire "fanotify"
Fanotify.watch("/data",
events: %i[create delete modify]
) do |event|
puts "#{event.mask.inspect} #{event.name}"
end
Example output
[:create] report.csv
[:modify] notes.txtThis example uses FID and filename reports, requiring Linux 5.9+. Unprivileged FID groups require Linux 5.13+ and a filesystem that supports file handles.
Build audit logs around create, delete, modify, and open events. Inspect file identity and name records from the kernel.
Explore the audit loggerAllow, deny, or defer permission events. Unanswered events are allowed when the handler returns, with cleanup built in.
Read the permission guideExplore pre-access range events for hierarchical storage. Experimental support needs Linux 6.14+ and an HSM-capable filesystem.
Explore lazy fetchingFanotify is built for Linux. Kernel features, filesystem support, and process capabilities determine which events you can use.
Check platform supportRuby 3.2+ and Linux 5.1+ with CONFIG_FANOTIFY. Newer report types need newer kernels.
Permission events and mount or filesystem marks need CAP_SYS_ADMIN. Permission handlers block the requesting process: keep them bounded and follow the handler safety rules.
The gem loads on macOS, BSD, and Windows, but Fanotify.supported? returns false. Run filesystem monitoring on Linux.