sudo log审核

杨沐涵

关注

阅读 69

2022-06-27


用系统自带的日志系统rsyslog

echo "Defaults      logfile=/var/log/sudo.log" >> /etc/sudoers#在visudo 中添加 howhy   ALL=(ALL)       ALL,!/usr/bin/passwd [a-zA-z]+,!/bin/su -

echo "local2.debug     /var/log/sudo.log" >> /etc/rsyslog.conf

或vi /etc/rsyslog.conf

# Save sudo log to sudo.log
local2.debug                              /var/log/sudo.log

systemctl restart rsyslog


精彩评论(0)

0 0 举报