Hi
We've enabled audit logging on security relevant files.
We see unnecessary chown and chmod accesses to the group-override file.
/etc/opt/quest/vas/group-override log entry:
----
type=PROCTITLE msg=audit(09/08/2017 08:22:46.341:28049) : proctitle…