4.3.3 Ensure sudo log file exists

Information

The Defaults logfile entry sets the path to the sudo log file. Setting a path turns on logging to a file; negating this option turns it off. By default, sudo logs via syslog.

Defining a dedicated log file for sudo simplifies auditing of sudo commands and creation of auditd rules for sudo.

Solution

Edit the file /usr/local/etc/sudoers or a file in /usr/local/etc/sudoers.d/ with visudo or visudo -f <PATH TO FILE> and add the following line:

Defaults logfile="<PATH TO CUSTOM LOG FILE>"

Example

Defaults logfile="/var/log/sudo.log"

Note:

- sudo will read each file in /usr/local/etc/sudoers.d, skipping file names that end in ~ or contain a . character to avoid causing problems with the package manager or editor temporary/backup files.
- Files are parsed in sorted lexical order. That is, /usr/local/etc/sudoers.d/01_first will be parsed before /usr/local/etc/sudoers.d/10_second.
- Be aware that because the sorting is lexical, not numeric, /usr/local/etc/sudoers.d/1_whoops would be loaded after /usr/local/etc/sudoers.d/10_second.
- A consistent number of leading zeroes in the file names can be used to avoid such problems.

Impact:

WARNING: incorrectly Editing the sudo configuration can cause sudo to stop functioning. Always use visudo to modify sudo configuration files.

If not correctly managed, the creation of additional log files can exhaust disk space. Configure logrotate to manage the sudo log in accordance with your local policy.

See Also

https://workbench.cisecurity.org/benchmarks/19044

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-3, 800-53|AU-3(1), 800-53|AU-7, 800-53|AU-12, CSCv7|6.3

Plugin: Unix

Control ID: e0975d4c8e59bc68225e19dfecbd1779182af7a6a502f91dbd732dd5bd549716