How to use auditd to monitor users elevating privileges to the root account
Issue
- We need to setup audit logs to monitor in linux server who is switching to root on server
- Configure Audit logs to find user elevated to the root account in Redhat Linux servers
Environment
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- auditd
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.