↑ ↓ select, Enter open, Esc close

Show commands run with sudo from the journal

Adjust the values, the command updates live
root@server
journalctl _COMM=sudo --since "7 days ago" --no-pager | grep 'COMMAND='

sudo logs every call with the calling user, working directory, target user and full command. The filter shows only these command lines from the selected time range. Useful for attributing system changes to a person and a point in time.

Note: Commands inside a root shell opened with sudo -i or sudo su are not recorded individually this way. With rsyslog, the entries are also in /var/log/auth.log.

Also searched as

  • sudo command history all users
  • who ran sudo commands
  • sudo log journalctl

Related one-liners

All in Security

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.