Prints all audit events tagged with the passwd_changes key, the records created by the matching auditctl watch rule. This is how you answer who touched a file and when. Narrow the window with -ts today or -ts recent.
Looking for more? Search all 7,657 commands — works offline, in English or Spanish, and fixes typos.