https://bugs.kde.org/show_bug.cgi?id=370608
--- Comment #5 from kolAflash <kolafl...@kolahilft.de> --- I used auditctl / ausearch as suggested, but got only this line after the file was deleted: type=CONFIG_CHANGE msg=audit(10/21/16 13:06:51.010:163) : auid=unset ses=unset op="updated_rules" path=/tmp/xauth-1000-_0 key=(null) list=exit res=yes I'm having no idea what type=CONFIG_CHANGE should indicate. Guess normally ausearch should give me the program's name or pid. The only thing I was able to find by that message was this bug report, which has a similar ausearch result. https://bugzilla.redhat.com/show_bug.cgi?id=567914 type=CONFIG_CHANGE msg=audit(1270141789.105:19355): auid=500 ses=5 op="updated rules" path="/home/kavol/.Xauthority" key=(null) list=4 res=1 -- You are receiving this mail because: You are watching all bug changes.