In the Changed files section of /var/log/aide/aide.log there are prefixes on each line starting with f or d. These signify what aspects of the file has changed, but I can't seem to track down what they mean. (Obviously I could look at the detailed data for the file further down the log file, but a definitive reference for the summary lines is important for grepping.)
Here are some examples:
f >.p.. mci.CA. .: /etc/passwd-
d =.... mc.. .. .: /bin
f =.... mci.C.. .: /bin/ip
d =.... mc.n A. .: /u1/home
This is detailed in the
aide.conf
manual page, reproduced here for completeness, and is a configurable attribute of the generated reports: