1.3.3 Ensure sudo log file exists

Information

sudo can use a custom log file A sudo log file simplifies auditing of sudo commands

Solution

edit the file /etc/sudoers or a file in /etc/sudoers.d/ with visudo -f and add the following line: Defaults logfile="<PATH TO CUSTOM LOG FILE>" **Example Defaults logfile="/var/log/sudo.log" Impact: editing the sudo configuration incorrectly can cause sudo to stop functioning

See Also

https://workbench.cisecurity.org/files/2518

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12, CSCv7|6.3

Plugin: Unix

Control ID: 67091e09623313a2f71b415533e25457d6abaa662e4f4dcd5c2921301ca3e1c4