Score:0

Auditd to capture user runing command

in flag

I have a audit watch/rule that logs every command executed, but it dose not mention/logs which user executed the command!

Do we have any workaround for that?

Talaat Etman avatar
gt flag
did you mean bash history in home directory it save all user executed commands
Syed Aqeel avatar
in flag
no, not the bash history, the actual commands for example, a user puppet cat /etc/shadow and it will log cat /etc/shadow not the user name executed the command.
Talaat Etman avatar
gt flag
var/log stores all loges
Syed Aqeel avatar
in flag
Yes, but not the executed commands !!
I sit in a Tesla and translated this thread with Ai:

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.