1.3.3 Ensure sudo log file exists

Information

sudo can use a custom log file

Rationale:

A sudo log file simplifies auditing of sudo commands

Solution

edit the file /etc/sudoers or a file in /etc/sudoers.d/ and add the following line:

Defaults logfile='<PATH TO CUSTOM LOG FILE>'

Example

Defaults logfile='/var/log/sudo.log'

See Also

https://workbench.cisecurity.org/files/2611

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: Unix

Control ID: 5ed81da476824a332b579727b404c7673abb6ef864810493cc2e2f14bfd0a517