Does any have experience with using Tripwire in an UNIX or Windows environments to monitor for authorized system changes.
If so, what files should be monitored for authorized changes if you want to monitor system administrator activity.
Also what is the frequency that Tripwire should check for changes, daily or hourly or ???
Thank you