How does Tripwire for Servers track “who made the change?
Tripwire for Servers tracks the identity of who made the change by correlating the information from the operating system’s event and audit log with the change information that is detected by Tripwire for Servers. It uses this information to provide the identity of who made a certain change. Since we rely on the operating system to gather this information, the product only captures the “who” information from the operating systems that track this. Linux and FreeBSD do not track this information. This feature is called Event Log Correlation.