Enable SSH audit logging
Learn how to set up SSH audit logging on a Linux Ubuntu server
Set up SSH audit logging
sudo nano /etc/ssh/sshd_config LogLevel VERBOSE SyslogFacility AUTHPRIVsudo apt update && sudo apt install auditdsudo nano /etc/audit/auditd.conf auditd -l -f /var/log/audit/audit.log max_log_file = 50 max_log_file_action = keep_logssudo nano /etc/audit/rules.d/audit.rules -w /var/run/sshd -p wa -k sshd -a exit,always -F arch=b64 -F euid=0 -S session -a exit,always -F arch=b64 -F euid=0 -S execve -k ssh_commandssudo systemctl restart ssh.servicesudo systemctl restart audit.service
Last updated
Was this helpful?
