<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sudo Log in Operating System - Linux</title>
    <link>https://community.hpe.com/t5/operating-system-linux/sudo-log/m-p/4473040#M37778</link>
    <description>That should read:&lt;BR /&gt;&lt;BR /&gt;If "su -" is allowed, sudo won't know anything beyond that and won't log the shell activity.</description>
    <pubDate>Tue, 04 Aug 2009 18:21:56 GMT</pubDate>
    <dc:creator>Jeff_Traigle</dc:creator>
    <dc:date>2009-08-04T18:21:56Z</dc:date>
    <item>
      <title>Sudo Log</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sudo-log/m-p/4473035#M37773</link>
      <description>I need a suggestion. We are enabling sudo access to our servers. Does sudo offers any type of logging? How can we enable that in RHEL?&lt;BR /&gt;&lt;BR /&gt;I have another question. Lets say we have granted some users root access using sudo like sudo su -. Is there any way, we can monitor that user activity after he has switched to root using sudo su -</description>
      <pubDate>Tue, 04 Aug 2009 16:11:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sudo-log/m-p/4473035#M37773</guid>
      <dc:creator>Waqar Razi</dc:creator>
      <dc:date>2009-08-04T16:11:37Z</dc:date>
    </item>
    <item>
      <title>Re: Sudo Log</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sudo-log/m-p/4473036#M37774</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://linux.about.com/od/commands/l/blcmdl8_sudo.htm" target="_blank"&gt;http://linux.about.com/od/commands/l/blcmdl8_sudo.htm&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;By default sudo logs to /var/log/messages or whatever syslog is set to.&lt;BR /&gt;&lt;BR /&gt;It can be configured to use its own log file.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Tue, 04 Aug 2009 16:22:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sudo-log/m-p/4473036#M37774</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2009-08-04T16:22:02Z</dc:date>
    </item>
    <item>
      <title>Re: Sudo Log</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sudo-log/m-p/4473037#M37775</link>
      <description>Do you know how can we setup it in /etc/sudoers file?</description>
      <pubDate>Tue, 04 Aug 2009 16:23:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sudo-log/m-p/4473037#M37775</guid>
      <dc:creator>Waqar Razi</dc:creator>
      <dc:date>2009-08-04T16:23:40Z</dc:date>
    </item>
    <item>
      <title>Re: Sudo Log</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sudo-log/m-p/4473038#M37776</link>
      <description>I have setup /var/log/sudo.log for logging sudo activities. I have the following questions now:&lt;BR /&gt;&lt;BR /&gt;1- After switching to sudo root access by using sudo su -, I can see the switch in the /var/log/sudo.log file:&lt;BR /&gt;&lt;BR /&gt;Aug  4 13:49:40 : t-aabb : TTY=pts/1 ; PWD=/home/t-aabb ; USER=root ;&lt;BR /&gt;    COMMAND=/bin/su -&lt;BR /&gt;&lt;BR /&gt;But after that, sudo.log is not logging any activities performed by user imran as root. For instance, lets say the user now issues shutdown -r now command after switching to root using sudo su -, How can I configure sudo to log these activities as well.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 04 Aug 2009 16:57:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sudo-log/m-p/4473038#M37776</guid>
      <dc:creator>Waqar Razi</dc:creator>
      <dc:date>2009-08-04T16:57:05Z</dc:date>
    </item>
    <item>
      <title>Re: Sudo Log</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sudo-log/m-p/4473039#M37777</link>
      <description>You can't. Sudo will only log the command it allows. If "su -" is allowed, sudo won't know anything about it and won't log it. Some system command auditing is needed... preferably one that has a facility to log remotely to a system the user doesn't have the ability to potential access and modify log records. Relying on shell histories and local logs, especially when allowing a root shell, isn't very effective. :)</description>
      <pubDate>Tue, 04 Aug 2009 18:20:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sudo-log/m-p/4473039#M37777</guid>
      <dc:creator>Jeff_Traigle</dc:creator>
      <dc:date>2009-08-04T18:20:37Z</dc:date>
    </item>
    <item>
      <title>Re: Sudo Log</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sudo-log/m-p/4473040#M37778</link>
      <description>That should read:&lt;BR /&gt;&lt;BR /&gt;If "su -" is allowed, sudo won't know anything beyond that and won't log the shell activity.</description>
      <pubDate>Tue, 04 Aug 2009 18:21:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sudo-log/m-p/4473040#M37778</guid>
      <dc:creator>Jeff_Traigle</dc:creator>
      <dc:date>2009-08-04T18:21:56Z</dc:date>
    </item>
  </channel>
</rss>

