Logstash filter and patterns for sudo logs
Switch branches/tags
Nothing to show
Clone or download
Fetching latest commit…
Cannot retrieve the latest commit at this time.
Permalink
Type Name Latest commit message Commit time
Failed to load latest commit information.
conf.d
patterns.d
LICENSE
README.md

README.md

Logstash filter and patterns for sudo

This is a simple filer and pattern for sudo logs in linux (tested on ubuntu logs)

There is an extra field added

sudo.allowed true or false for graphing and alerting