1.3.3 Ensure sudo log file exists

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

sudo can use a custom log file

Rationale:

A sudo log file simplifies auditing of sudo commands

Solution

edit the file /etc/sudoers or a file in /etc/sudoers.d/ and add the following line:

Defaults logfile='<PATH TO CUSTOM LOG FILE>'

Example

Defaults logfile='/var/log/sudo.log'

See Also

https://workbench.cisecurity.org/files/2611

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: Unix

Control ID: 579d6cc2a003068d3eafd69ebf7675ee35052171380b2b1313333a6386e049aa