sudoreplay command examples

sudoreplay command examples

sudoreplay — replay sudo session logs

List sessions run by user millert:

# sudoreplay -l user millert

List sessions run by user bob with a command containing the string vi:

# sudoreplay -l user bob command vi

List sessions run by user jeff that match a regular expression:

# sudoreplay -l user jeff command '/bin/[a-z]*sh'

List sessions run by jeff or bob on the console:

# sudoreplay -l ( user jeff or user bob ) tty console

Leave a Reply

Your email address will not be published. Required fields are marked *