创建审计日志文件存放目录
[root@localhost-01 ~]# mkdir -p /usr/local/domob/records/
更改目录权限,让其可写,不可删
chmod 777 /usr/local/domob/records/
[root@localhost-01 ~]# chmod +t /usr/local/domob/records/
vim /etc/profile 在最后添加下面的代码//系统级别全局变量配置文件
[root@localhost-01 ~]# vim /etc/profile
命令审计:
if [ ! -d /usr/local/domob/records/${LOGNAME} ]
then
mkdir -p /usr/local/domob/records/${LOGNAME}
chmod 300 /usr/local/domob/records/${LOGNAME}vim
fi
export HISTORY_FILE="/usr/local/domob/records/${LOGNAME}/bash_history"
export PROMPT_COMMAND='{ date "+%Y-%m-%d %T ##### $(who am i |awk "{print \$1\" \"\$2\" \"\$5}") #### $(history 1 | { read x cmd; echo "$cmd"; })"; } >>$HISTORY_FILE'
#刷新配置
[root@localhost-01 ~]# source /etc/profile