# Append these lines to /etc/clamav/clamd.conf (as root) to enable on-access # scanning. Adjust the paths for your own setup before applying. # # sudo tee -a /etc/clamav/clamd.conf < setup/clamd-onaccess.conf # sudo systemctl enable --now clamav-clamonacc.service # Directory tree to watch. /home covers every user's files. OnAccessIncludePath /home # Required: exclude clamd's own scanning process from triggering itself. OnAccessExcludeUname clamav OnAccessExcludeUID 0 # Skip scanning huge files (adjust as needed). OnAccessMaxFileSize 100M # fanotify watches a whole mount, not a subtree, so this must name the # mount that OnAccessIncludePath lives on (usually the same as the path # above, or "/" if /home is not a separate mount on your system). OnAccessMountPath /home # Example: exclude a directory that rewrites its own files constantly # (a sync client's internal database, a browser cache, etc.). Without # excludes like this, a busy app can flood the scanner and pin a CPU # core. Add one OnAccessExcludePath line per directory you need to skip. #OnAccessExcludePath /home/YOUR_USER/.local/state/syncthing