How to configure auditd to log every time a specific command is run.

Solution Verified - Updated -

Issue

The Linux Auditing system is a great way to get an audit trail of everything that happens on your system. But the vast amount of logging and information that is generated can be overwhelming. This is where auditd comes in. auditd is the userspace component to the Linux Auditing System. It's responsible for writing audit records to the disk. By configuring audit rules, you can specify what actions to log.

Environment

  • Red Hat Enterprise 7
  • Red Hat Enterprise 8

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content