Enable Auditing
Make sure audit logs capture all administrative actions, including commands
with arguments.
-
Log in to one of the compute servers and access the host console as
superuser.
See Log into a Compute Server.
-
Configure the audit facility.
# auditconfig -setpolicy +argv
# auditconfig -setflags lo,ad,ex >& /dev/null
# auditconfig -setpolicy +zonename