https://github.com/osquery/osquery logo
#general
Title
# general
m

Mike S.

01/11/2023, 4:31 PM
Hello team - I have a newbie question, hopefully that's ok to post! I am attempting to monitor the shell_history of a Linux system (Ubuntu). Specifically I am looking for sudo activity. When I run SELECT * from shell_history using my account, I can see some of the sudo commands I have performed, which is good. But any new sudo commands (or non-sudo commands) are not showing up in this table (example: sudo vi /etc/sudoers). I suspect I'm missing something simple, just not sure what it is.