files are getting deleted automatically in user's home directory

Latest response

We have a two nfs shares from EMC storage mounted. The users home directory are created over there. The files in the users home directory are getting deleted automatically every 15 days or so. I Checked and found no cron jobs running. How to find out who its getting deleted and need to fix it.

Responses

Are those shares mounted by other systems as well with "no_root_squash"? If so, then those users home directory could be accessed and modified by root of another system,, first look at the issue...

You could enable auditing on the system and add users home directories to be audited and then track it later. Another option, i could suggest is to configure aide to monitor changes on those users home directories.

How to use and configure aide (Advanced Intrusion Detection Environment) in Red Hat Enterprise Linux?

Hi Sadashiva,

Thanks for the reply. Yes the shares are mounted on the other servers also. server1:/root_vdm_2/Cluster_share /home nfs hard,intr,timeo=5,retry=2,defaults 0 0

If the same path is being used on multiple locations then there may be chances of files getting modified/deleted (provided proper permissions) unless separated as such like this

/shared/forclient1      <client1IP>(rw,no_root_squash) 
/shared/forclient2      <client2IP>(rw,no_root_squash)

How are the shares defined in nfs server? , check the /etc/exports file. If you are sure that those files saved in the central nfs server gets removed automatically then better option is to enable auditing for those shared nfs files on all the systems which got accesss.

When I see wording around file-persistence like "getting deleted automatically every 15 days or so", I have to wonder if someone hasn't enabled a backup service that's operating in archive mode (typically, archive backup jobs do save-and-delete where regular backup jobs just save). May not be the case here, but it's not inconsistent with such a (mis)configuration.

I saw it before... In that case the broblem was a snapshot's volume or virtual machine getting restored.. Check your snapshot configuration in your storage system.. look at audit trails to see if some snapshot were restored.

Just another guess, if some person with rights is doing an rsync for archiving/backup perposes, they may have used the --delete argument and is pushing the wrong way??!

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.