Why a single auditd rule is better than scattered syslog entries
When you run sudo, you’re stepping into privileged territory. Most distros ship a sudo wrapper that dumps a message into syslog. That message can be noisy, hard to sift through, and it doesn’t survive a clean‑up or a reboot. A dedicated auditd rule, on the other hand, captures every sudo invocation in a structured, tamper‑evident format. Couple that with a tiny logrotate config, and you get a reliable audit trail that sticks around long after the machine has been rebooted or the disk wiped.