---
title: Linux Audit Report
slug: kronpam-reference-guide-3-5-0/linux-audit-report
description: The Linux Local User Audit Report is a powerful tool for assessing the security of local Linux accounts. With the ability to configure and execute reports manually or automatically, users can stay on top of their system's security status. Easily access de
docTags: 
createdAt: 2022-08-02T08:54:44.000Z
---

The Linux Local User Audit Report is used to report the current security status of local Linux accounts.

**Create the Report Configuration**

1. Navigate to **Audit Report&#x20;**> **Linux Audit Report**.
2. Open the **Report Configuration** tab.
3. Create a report configuration by completing the fields. The Report job can be executed manually or periodically (as scheduled).

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/8d9ROqPQ4bvGnxbgGIkfy_image.png "Linux Audit Report Configuration")

To execute the report manually, click the **Options** pop-up menu button and select **Run**.

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/__iPEjuEf1jCXPKAAdjM3_image.png "Report List")

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/aMW_KCXhuxeqy8ozZmjyE_image.png "Run Linux Audit Report")

To execute the Report periodically, the Scheduled field needs to be configured in the Report Configuration. The period can also be configured from the Jobs Scheduler by editing the LinuxAuditJob.

:::hint{type="info"}
For the purposes of the Audit Report, the selected device groups must have the globalUsername and globalPassword properties defined. See also section  [Device Group Properties](https://app.archbee.com/docs/jsymInd0w_SXayMlKGOmR/2lPRCyQIR220XUzuT0ZT_). To access the report detail, the user defined as “**globalUsername**” should be a privileged user. Also, If the globalusername is a sudo user and the **sudo&#x20;**&#x63;ommand execution is required to get report details, the **useSudoForLinuxAuditReport** device group property must be defined as **true** on the Device Group. After this definition, the **Sudoers** column is added to the **Linux Audit Report Details** table and the globalusername sudo user will write **YES** here.
:::

**Report Details**

When the job finishes, reports are listed in the Reports tab. To access the reports:

1. Navigate to **Audit Report&#x20;**> **Linux Audit Report**.
2. Open the **Report** tab.
3. Click the **Options** drop-down menu button and select **Show Details**.

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/BkFvceMzMVjh9p_cc5wFK_image.png "Linux Audit Report")

Report details are shown in the Linux Audit Report Details section:

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/TikSF24PCyJFAcO-31S2-_image.png "Linux Audit Report Details")

**Dashboard**

1. Navigate t&#x6F;**&#x20;Audit Report&#x20;**> **Linux Audit Report**.
2. Open the **Dashboard&#x20;**&#x74;ab.
3. Choose the desired fields and click the **Display Reports** button.

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/PYg7X1a4TXAn8QumK7uoq_image.png "Linux Audit Report Dashboard")

:::hint{type="info"}
If you want to exclude service accounts from the audit reports, you need to defin&#x65;**&#x20;accountToExcludeFromLinuxAuditReport** as a property at the device group level. By defining this property and setting service accounts, users can distinguish service accounts and application accounts by excluding defined accounts from Linux audit reports.
:::

