13

Where are unauthorized sudo attempts reported to?

When you attempt to use sudo, and are not allowed, a message says that the attempt will be reported.

Is this only reported in /var/log/auth.log? Is there another place? The reason I ask, is because the log contains so much that it's not a very good way of viewing often.

muru
  • 193,181
  • 53
  • 473
  • 722
Frantumn
  • 1,407
  • 4
  • 19
  • 29

2 Answers2

12

It is reported in that file in ubuntu. It quite easy to change that. Just add this line in your /etc/sudoers file. Use sudo visudo to edit the file.

Defaults    logfile=/var/log/sudo.log 

You can change the file name to whatever you think is appropriate.

heemayl
  • 90,425
  • 20
  • 200
  • 267
McNisse
  • 1,823
  • 1
  • 16
  • 16
5

It is also sent by e-mail to root. If you want to have it sent to your user account instead, you can set an alias in /etc/aliases. In addition, if your system is configured properly to send e-mail to the outside world, you can alias it to any e-mail address. (To read e-mail sent to your local account, you can use, e.g., mutt.)

fkraiem
  • 12,344
  • 4
  • 33
  • 38