auditctl -w /var/log/messages -p rwa -k message_file_access
if you would like to make this audit rule to be permanently configured then add it to the below file.
/etc/audit/rules.d/audit.rules
Red Hat
Learning Community
A collaborative learning environment, enabling open source skill development.