Monitoring paths
Good path scoping keeps FIM useful. Monitor what proves integrity and skip directories that change constantly by design.
High-value targets
- Package-managed binaries
- Service unit files and init configs
- Application config roots
- TLS certificates and private keys
- Cron, sudoers, and auth policy files
Paths to exclude carefully
- Logs and spool directories
- Caches and temporary build output
- Highly dynamic runtime state, unless you have a compliance reason
Pattern tips
Prefer explicit paths over broad wildcards. When using globs, pair includes with excludes so one noisy subtree does not dominate the feed.