-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Aug 16, 2010, at 6:23 PM, jplee3 wrote: > Hi all, > > Just wondering if OSSEC has the ability to capture all commands run > after sudoing or su'ing to root (or another privileged user, etc).
I think this is outside of the scope of ossec.. Sudo itself doesn't log that information (at least, not by default), and it doesn't appear in the audit.log either.. - --------------------------- Jason 'XenoPhage' Frisvold [email protected] - --------------------------- "Any sufficiently advanced magic is indistinguishable from technology." - - Niven's Inverse of Clarke's Third Law -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.14 (Darwin) iEYEARECAAYFAkxsRCEACgkQ8CjzPZyTUTRHuQCfYPs8sJoIj5697P279vOlfjKZ klAAoJqD2WvSSdFgP4nlIdSfKbvmkt8N =okLD -----END PGP SIGNATURE-----
