Audit trail in Linux

It is probably a good idea to have audit enabled on the server. Even though a hacker could disable it (if he was able to penetrate the server and gain root), there is still chance that he will not check for audit to be enabled.

Read more…