You're almost there! Please answer a few more questions for access to the Applications content. Complete registration
Interested in joining? Complete your registration by providing Areas of Interest here. Register
Note!! Please register for a free account to access the full content and also to participate in Q&A in the community

Audit root level activities

Hi Team,

We are using an Oracle DBCS VM running on Oracle Enterprise Linux (OEL) 8.

Currently, we have a group of users with root access. Since this unrestricted root access cannot be removed at this time, one of the team members recommended implementing the following controls to audit root-level activities:

Named SSH accounts for individual user identification(This step is done)
Sudo I/O logging
auditd command auditing
Centralized log retention and monitoring

We would like your guidance on implementing this approach. Could you please provide the step-by-step procedure, including any prerequisites, configuration details, and best practices, to enable comprehensive auditing of root-level activities on the server?

Howdy, Stranger!

Log In

To view full details, sign in.

Register

Don't have an account? Click here to get started!