WAZUH All Commands monitor

604 views Asked by At

How to monitor each and every command executed by user, even in sudo level. I have configured audit rules and they are appearing in audit.logs, but I want to view each command timely from server to Kibana/wazuh manager. enter image description here

1

There are 1 answers

0
Sulaiman On

Auditd share complete commands and users UID too with wazuh if configured properly. So I just added those columns from list in Kibana and now data is apearing fine.