How to configure auditd to log every time a specific command is run.

Solution In Progress - Updated -

Issue

The Linux Auditing system is a great way to get an audit trail of everything that happens on your system. But the vast amount of logging and information that is generated can be overwhelming. This is where auditd comes in. auditd is the userspace component to the Linux Auditing System. It's responsible for writing audit records to the disk. By configuring audit rules, you can specify what actions to log.

Environment

Red Hat Enterprise 7

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.

Current Customers and Partners

Log in for full access

Log In
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.