How to capture the full command root logs from graylog server

how to capture the full command root logs from graylog server : for example when we run command with root login " lsmod | grep -i usb" - it is not showing logs with full command. showing lsmod only

Can you give some more detail on what and how you are pulling those logs? Are you talking about .bash_history? Are you using filebeat or nxlog to retrieve those? What OS are you using? CentOS, Ubuntu, FreeBSD?

** I moved your question to Graylog Central, where questions are asked… :smiley:

Hi The OS is CentOS 7.9 and using rsyslod for collecting logs from server.

When I run any command like lsmod | grep -i usb —> it is not showing in graysys log events that I executed total command ( lsmod | grep -i usb) … It shows only lsmod

Hey @bhagyaiah

Not sure what you trying to do. Could you answer @tmacgbay questions?

Your environment and what you are doing is a complete black box… you need to provide more information for us to help you. Here are some posts on how to give more details:

1 Like

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.