Why doesn't "aureport --tty" show non-root user commands even with "enable=*" option to "pam_tty_audit.so"?
Issue
-
Audit log is not showing sudo access.
-
pam_tty_audit only logs root commands.
Environment
- Red Hat Enterprise Linux 6.x
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.