1.3.3 Ensure sudo log file exists

Information

sudo can use a custom log file A sudo log file simplifies auditing of sudo commands

Solution

edit the file /etc/sudoers or a file in /etc/sudoers.d/ with visudo -f and add the following line:

Defaults logfile='<PATH TO CUSTOM LOG FILE>'

Example
Defaults logfile='/var/log/sudo.log'

Impact: editing the sudo configuration incorrectly can cause sudo to stop functioning

See Also

https://workbench.cisecurity.org/files/2521

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12, CSCv7|6.3

Plugin: Unix

Control ID: 6d550ecc947f48604198508cc311e8a5a9d48dd097ad21a83b10ba8de0412e2a