Neo23x0 / auditd

Best Practice Auditd Configuration
Apache License 2.0
1.51k stars 261 forks source link

I have difficulty in investigation #151

Closed hoanga2dtk68 closed 3 months ago

hoanga2dtk68 commented 3 months ago

image I am using your rule, it works quite well but I am having problems with making it difficult to investigate when there is a problem with the log recorded in the command. For example, when I use whoami or ifconfig to test, it only shows sh as shown in the image above. Is there any way to fix this?