Watching Under The Hood Of Tiger's Spotlight
Posted by
Hemos
on Mon May 23, 2005 07:11 AM
from the looking-at-it dept.
from the looking-at-it dept.
jaketheitguy writes "Over at KernelThread.com, Amit Singh has released a commandline app called FSLogger for looking under the hood of Tiger's Spotlight. You can watch all kinds of filesystem changes going on in realtime. The utility apparently intercepts and displays filesystem change data as it goes out to Spotlight from the kernel. It even tells you which app is making the changes. Looks like Apple has included some pretty powerful API's in Tiger and there may be some othre really interesting uses of this API as mentioned on the app's page. I for one would really like to be able to tell if somebody changed ANY files on my system without my knowledge. I think you can do that with Singh's program, but how do you make sure somebody cannot disable the program?"
This discussion has been archived.
No new comments can be posted.
Watching Under The Hood Of Tiger's Spotlight
|
Log In/Create an Account
| Top
| 43 comments
| Search Discussion
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.

Two in a row? (Score:1, Offtopic)
(Last Journal: Tuesday May 30 2006, @09:10AM)
Come on Hemos, lets have a hattrick
and oh... I for one welcome our new Spotlight overlords
Spotlight changed my life. (Score:4, Funny)
(http://www.dufftech.net/)
- Run Faster
- Jump Higher
- Score with the chicks
- Regrow lost hair!
Two stories in 20 minutes? (Score:1)
(http://www.mensa.org/ | Last Journal: Sunday July 13 2003, @08:43AM)
Recursion (Score:2, Funny)
So, this application would shine a spotlight on Spotlight? Is that anything like when you point a video camera at a monitor hooked up to the camera's output?
IDS Potential (Score:2)
(Last Journal: Friday February 13 2004, @10:23PM)
Interesting idea.
Where's "As Seen on TV" ... (Score:2)
He was very vocal about this sort of thing, and now he's gone very quiet. Almost as if he was an Apple employee who was given The Warning (tm) or... (obligatory Star Wars reference being used in shameless Karma whoring)
When I get some time, I'll read the article (thus breaking a long-running streak for me) and compare to ASoT's statements.
Tracking changes to the file system (Score:3, Informative)
Take a look at the kqueue(2) man page.
There are more details available at http://people.freebsd.org/~jlemon/papers/kqueue.pd f [freebsd.org]
Physical security essential (Score:1)
(http://slashdot.org/~davidwr/journal/ | Last Journal: Friday November 09, @09:19PM)
You can't, not withint guarenteeing physical security to the box.
If someone can pull your hard disk OR boot with their own media, all is lost.
Short of that, your question amounts to "how do I keep from getting rootkitted."
Re:Just use fs_usage (Score:1)
(Last Journal: Thursday October 06 2005, @01:38PM)
These guys are utter LORDS of the nt OS by any definiton. ( read their "About us" section and see just how A class it is. A Microsoft Most Valued Proffesional no less )
Anyway. There are filesystem access and notification tools around for nearly any os and its good to see OS X realy making a push with them instead of the way theyer usualy swept under the rug in most OSes publicity stuff (not that many oses have publicity to speak of lol )