Multiple values in a search option
I am using ausearch to parse my audit data. I would like to look for files with etc and var in the title or path. I can search each separately using -f etc or -f var. How can I combine them to make one search?
|
Hi, welcome to LQ!
I have never used ausearch ... Does it support mulitple -f statements? E.g., Code:
ausearch -f etc -f var [edit] Looking at man ausearch-expression ... Would Code:
ausearch -f "etc||var" [/edit] Cheers, Tink |
Slight mistake
In my original question, I wanted directories that had etc and var in the paths. My mistake. I would like to search for auditable events that have either etc or var in the path. I can try the || as suggested but I am probably sure this will not work. Is there a logical separation that will identify "or" as the separator or is "||" the "or" separator?
|
The "double pipe" *is* OR.
|
All times are GMT -5. The time now is 07:06 PM. |