How to track user activities in "sudo su -" session for audit purpose?
Issue
- Ordinary users are granted permission to switch to root via
sudo su -
to perform administrative tasks. - System audit log is enabled, however, it does not record all inputs and outputs.
- Command line activities must be recorded for audit purpose.
Environment
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- sudo
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.