Enable command logging on Linux hosts
Introduction
Command logging helps administrators monitor the commands executed by users on a Linux server. By configuring Bash and the system logger, every command entered by users can be recorded in a dedicated log file. This is useful for auditing user activity and troubleshooting unexpected changes on the server.
Prerequisites
- Root or sudo access to the Linux server
- SSH access to the server
rsyslogservice installed and running- Permission to modify system configuration files
Implementation
Step 1
Edit the Bash configuration file.
For most Linux distributions:
/etc/bashrc
For Ubuntu:
/etc/bash.bashrc
Step 2
Add the following line to enable command logging:
export PROMPT_COMMAND=’RETRN_VAL=$?;logger -p local6.debug “$(whoami) [$$]: $(history 1 | sed “s/^[ ][0-9]+[ ]//”) [$RETRN_VAL]”‘
Step 3
Configure the system logger by editing the syslog.conf or rsyslog configuration file and add the following entry:
local6.* /var/log/cmdlog.log
Step 4
Save the configuration file.
Step 5
Restart the rsyslog service.
For most Linux distributions:
/etc/init.d/rsyslog restart
For Ubuntu:
service rsyslog restart
Step 6
Execute a few commands and verify that they are being logged in:
/var/log/cmdlog.log
Conclusion
Enabling command logging provides an effective way to audit user activity on a Linux server. By recording all executed commands in a dedicated log file, administrators can monitor server usage, investigate issues, and improve overall system security.
