Select Your Language

Infrastructure and Management

Cloud Computing

Storage

Runtimes

Integration and Automation

  • Comments
  • Audit and record non-interactive ssh sessions

    Posted on

    I'm looking for a way to audit user commands while in a non-interactive sessions. For example when a user runs 'ssh cat /etc/shadow' or 'ssh /bin/bash' there is no log of the privileged execution within auditd. I've come across a few solutions to store the initial command within bash_history but not auditd.

    any help would be greatly appreciated!

    by

    points

    Responses

    Red Hat LinkedIn YouTube Facebook X, formerly Twitter

    Quick Links

    Help

    Site Info

    Related Sites

    © 2026 Red Hat