1.3.3 Ensure sudo log file exists

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

sudo can use a custom log file A sudo log file simplifies auditing of sudo commands

Solution

edit the file /etc/sudoers or a file in /etc/sudoers.d/ with visudo -f and add the following line:

Defaults logfile='<PATH TO CUSTOM LOG FILE>'

Example
Defaults logfile='/var/log/sudo.log'

Impact: editing the sudo configuration incorrectly can cause sudo to stop functioning

See Also

https://workbench.cisecurity.org/files/2521

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12, CSCv7|6.3

Plugin: Unix

Control ID: cbfd319ef08aa6133787c51f983a061cadaf93cf5d68cf69d7612fcccaf2c552