Step 1: Create Log Directory
sudo mkdir -p /var/log/sudo-commands
sudo chmod 750 /var/log/sudo-commandsStep 2: Configure Sudo Logging
sudo visudoAdd:
Defaults log_output
Defaults logfile=/var/log/sudo-commands/sudo.log
Defaults log_year
Defaults log_host
Defaults syslog=auth
Defaults loglinelen=0Step 3: Use sudoreplay to Playback
sudo sudoreplay -l
sudo sudoreplay session_idStep 4: Monitor Logs
sudo tail -f /var/log/sudo-commands/sudo.log