Bill--
IANAAE (I Am Not An Aide Expert :), but here's one of my AIDE configs
for a Postfix server we have:
most=p+i+n+u+g+s+md5
/sbin most
/bin most
/lib most
/boot most
/usr most
/opt most
/etc most
!/**~
!/**.cfsaved
!/etc/ld.so.cache$
!/etc/printcap$
!/etc/lvm/.cache$
!/etc/mtab$
!/etc/aide$
!/etc/cups$
!/etc/nagios/*
!/etc/postfix/prng_exch
!/usr/share$
!/etc/prelink.cache$
!/etc/ssh/ssh_known_hosts$
!/usr/local/var$
!/usr/local/maint$
!/etc/mail/spamassassin/local.cf$
I'm not sure how *good* that config is; generally, I don't get too
many changes to my db, but we've also never had an intrusion (that I
know of :), so I'm not sure if this would alert me or not.
HTH.
Chris St. Pierre
Unix Systems Administrator
Nebraska Wesleyan University