Where Does AIDE Store Its Database?
AIDE reads rules from /etc/aide with the reference database in /var/lib/aide built by init.
Last updated
AIDE splits config from its reference database cleanly. Rules in /etc/aide name which files to hash with what attributes. The compiled database lands in /var/lib/aide after running init.
Checks compare live files against that reference copy. Updating the system means rebuilding the database afterward. Keep an offline copy of the reference for meaningful tamper detection.
Where AIDE stores this, by platform
/var/lib/aide/aide.db
Reference hashes built by init live here. Rules sit in /etc/aide/aide.conf. Rebuild after every legitimate system change.
Frequently asked questions
How do I initialize AIDE?
Run the init command to build the reference database from current files, then move it into place. Schedule checks after package updates. Review every diff before rebuilding.
Why does AIDE report everything changed?
The reference predates legitimate updates or log rotation. Rebuild after approved changes only. Exclude volatile paths in rules to cut noise.
Notice an outdated path? Let us know.