What is a one sentence summary of your feature request?
Ability to monitor, alert and block actions or commands on Linux
Please describe your idea in detail. What is your problem, why do you feel this idea is the best solution, etc.
Need the ability to monitor, alert and block for set of prohibited actions or commands like shutdown a linux. For example, if a user tries to shut down a machine, the NPS administrator should get an alert, and the action should be blocked.
How do you currently solve the challenges you have by not having this feature?
We monitor the SIEM for events after the fact but cannot detect or alert in real-time.