Skip to content

Commit

Permalink
Merge pull request #3355 from sever-sever/T6109
Browse files Browse the repository at this point in the history
T6109: Fix remote logging for sudo commands
  • Loading branch information
c-po authored Apr 23, 2024
2 parents f3c36e2 + 7164ad4 commit 5486417
Showing 1 changed file with 15 additions and 15 deletions.
30 changes: 15 additions & 15 deletions src/etc/rsyslog.conf
Original file line number Diff line number Diff line change
Expand Up @@ -15,21 +15,6 @@ $KLogPath /proc/kmsg
#### GLOBAL DIRECTIVES ####
###########################

# The lines below cause all listed daemons/processes to be logged into
# /var/log/auth.log, then drops the message so it does not also go to the
# regular syslog so that messages are not duplicated

$outchannel auth_log,/var/log/auth.log
if $programname == 'CRON' or
$programname == 'sudo' or
$programname == 'su'
then :omfile:$auth_log

if $programname == 'CRON' or
$programname == 'sudo' or
$programname == 'su'
then stop

# Use traditional timestamp format.
# To enable high precision timestamps, comment out the following line.
# A modern-style logfile format similar to TraditionalFileFormat, buth with high-precision timestamps and timezone information
Expand Down Expand Up @@ -60,6 +45,21 @@ $Umask 0022
#
$IncludeConfig /etc/rsyslog.d/*.conf

# The lines below cause all listed daemons/processes to be logged into
# /var/log/auth.log, then drops the message so it does not also go to the
# regular syslog so that messages are not duplicated

$outchannel auth_log,/var/log/auth.log
if $programname == 'CRON' or
$programname == 'sudo' or
$programname == 'su'
then :omfile:$auth_log

if $programname == 'CRON' or
$programname == 'sudo' or
$programname == 'su'
then stop

###############
#### RULES ####
###############
Expand Down

0 comments on commit 5486417

Please sign in to comment.