10 Quick Tips About sudo command for Linux systems

1 Response

  1. Vince SH says:

    I always include the following lines in my /etc/sudoers:

    Defaults logfile = /var/log/sudo.log, log_host, log_year
    Defaults log_input, log_output, iolog_dir = /var/log/sudo-io/%{user}

    The first line just adds hostname and the year parameter in /var/log/sudo.log. For viewing the logs from multiple servers, these parameters allow easier queries by hostname and date.

    The second line is where the magic happens. This line tells sudo to log all input and output of each session. Using the sudoreplay command, I can replay any sudo session as though I was watching it happen live. The sudoreplay is great when people come to you and say, “I don’t know what I did, but something is broken.” Using the sudoreplay command, you will know EXACTLY what that person did.

Leave a Reply

Your email address will not be published. Required fields are marked *