How to configure audit rules to capture user activity for grep or egrep commands.
Issue
- How do I identify which user has executed the
grep -r -i
command using audit rules?
Environment
- Red Hat Enterprise Linux
- Auditd
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.