1.3.3 Ensure sudo log file exists

Information

sudo can use a custom log file A sudo log file simplifies auditing of sudo commands

Solution

edit the file /etc/sudoers or a file in /etc/sudoers.d/ with visudo -f and add the following line: Defaults logfile="<PATH TO CUSTOM LOG FILE>" **Example Defaults logfile="/var/log/sudo.log" Impact: editing the sudo configuration incorrectly can cause sudo to stop functioning

See Also

https://workbench.cisecurity.org/files/2518

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12, CSCv7|6.3

Plugin: Unix

Control ID: 7b5d25f12468afbbb69e48bec288371a57861ea4f2620793a0e77fb8afd6b9b4