> Source: [sk99134](https://support.checkpoint.com/results/sk/sk99134)

# sk99134 - How to Add Logging for Bash Shell Commands in Gaia OS

| Property | Value |
|----------|-------|
| Solution ID | sk99134 |
| Date Created | 2014-04-07 |
| Last Modified | 2026-08-10 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server, Multi-Domain Security Management Server |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R82.10, R82, R81.20, R82.10, R81 (EOS), R81.10 (EOS), R81 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82 |
| OS | Gaia |

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R82.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm) starting from Take 36

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

**Warning - Commands containing a password can be exposed as part of the logged commands. These passwords can be visible by any user.**

### Procedure for R80.30 - R82

Show / Hide this section  
Follow these steps to add logging of Bash shell (Expert mode) commands to */var/log/messages* file:

1. Connect to command line on Gaia machine (over SSH or console.)  

2. Log in to Expert mode.
3. Modify the ***/etc/security/pam_env.conf*** file:

   1. Back up the current */etc/security/pam_env.conf* file:

      ***\[Expert@HostName\]# cp /etc/security/pam_env.conf{,_ORIGINAL}***
   2. Add BASH_LOGGER to the */etc/security/pam_env.conf* file:

      ***\[Expert@HostName\]# echo 'BASH_LOGGER DEFAULT="ON"' \>\> /etc/security/pam_env.conf***
4. Modify the ***/etc/cli.sh*** file:

   1. Back up the current */etc/cli.sh* file:

      ***\[Expert@HostName\]# cp /etc/cli.sh{,_ORIGINAL}***
   2. Add BASH_LOGGER to the */etc/cli.sh* file:

      ***\[Expert@HostName\]# sed -i '/Now launch the shell/a export BASH_LOGGER="ON"' /etc/cli.sh***
5. Modify the ***/etc/profile*** file:

   1. Back up the current */etc/profile* file:

      ***\[Expert@HostName\]# cp /etc/profile{,_ORIGINAL}***
   2. Comment out LOGNAME in the */etc/profile* file:

      ***\[Expert@HostName\]# sed -i 's/LOGNAME=/#LOGNAME=/' /etc/profile***
6. Modify the ***/etc/sudoers*** file:

   1. Back up the current */etc/sudoers* file:

      ***\[Expert@HostName\]# cp /etc/sudoers{,_ORIGINAL}***
   2. Make a tmp copy of the /etc/sudoers file to edit:

      ***\[Expert@HostName\]# cp /etc/sudoers /tmp/sudoers***
   3. Add BASH_LOGGER and LOGNAME to the temp file:

      **\[Expert@HostName\]# sed -i 's/XAUTHORITY/XAUTHORITY BASH_LOGGER LOGNAME/' /tmp/sudoers**
   4. Replace the sudoers file with the temp file and remove the temp:  

      **\[Expert@HostName\]# cp /tmp/sudoers /etc/sudoers
      \[Expert@HostName\]# rm /tmp/sudoers**

7. Modify the ***/etc/bashrc*** file:

   1. Back up the current */etc/bashrc* file:

      ***\[Expert@HostName\]# cp /etc/bashrc{,_ORIGINAL}***
   2. Add 'echo -ne "";' to the PS1 exports in the */etc/bashrc* file:

      ***\[Expert@HostName\]# sed -i 's/HOSTNAME:\`/HOSTNAME:\`echo -ne "";/' /etc/bashrc***

      **Important Notes:**
      * The syntax uses the **semicolon** and **backtick** characters.

      * On a **Security Gateway configured with MDPS** ([sk138672](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk138672), ) these messages may appear repeatedly in the `/var/log/messages` file for each Bash command:

        * `shell: cmd by admin: plane_name`
        * `shell: cmd by admin: cat /proc/self/nsid`

        The issue appears in:
        * R81.10 and higher
        * R81 Jumbo Hotfix Accumulator Take 34 and higher
        * R80.40 Jumbo Hotfix Accumulator Take 114 and higher

        The solution is to add "```echo -ne "";``" in these files:  
        Show / Hide this section  
        1. Modify the */etc/bashrc* file to prevent the "`shell: cmd by admin: plane_name`" message:

           1. **You already created the backup of this file.**

           2. Edit the current `/etc/bashrc` file in Vi editor:

              `[Expert@HostName]# vi /etc/bashrc`

              **from:**

              ``export PS1='[Expert@$HOSTNAME:`plane_name`]# '``

              **to:**

              ``export PS1='[Expert@$HOSTNAME:```**echo -ne "";**``plane_name`]# '``
           3. Save the changes in the file and exit Vi editor.

        2. Modify the */etc/profile.d/mdpsenv.sh* file to prevent the "`shell: cmd by admin: cat /proc/self/nsid`" message:

           1. Back up the current `/etc/profile.d/mdpsenv.sh` file:

              `[Expert@HostName]# cp /etc/profile.d/mdpsenv.sh{,_ORIGINAL}`
           2. Edit the current `/etc/profile.d/mdpsenv.sh` file in Vi editor:

              `[Expert@HostName]# vi /etc/profile.d/mdpsenv.sh`

              Change the code in the function "`plane_name()`"

              **from:**

              ``local plane=`cat /proc/self/nsid```

              **to:**

              ``local plane=```**echo -ne "";**``cat /proc/self/nsid```
           3. Save the changes in the file and exit Vi editor.

        3. Log out from all shells.

        4. Log in to the Expert mode.

      * On a **VSX Gateway** , the message "*shell: cmd by admin: cat /proc/self/vrf* " may appear repeatedly in the */var/log/messages* file.

        Show / Hide this section  
        As an immediate ***workaround*** , modify the ***/etc/bashrc*** file in this way:

        from
        *export PS1='\[Expert@$HOSTNAME:\`echo -ne "" ; cat /proc/self/vrf\`\]# '*

        to
        *export PS1='\[Expert@$HOSTNAME:\`echo -ne "" ; echo $VRF_NUMBER\`\]# '*

        or just to
        *export PS1='\[Expert@$HOSTNAME:\`echo -ne "" \`\]# '*
   3. Save the changes and exit from Vi editor.

   4. Log out from **all** shells.

   5. Log in to Expert mode.

<!-- -->

**Note:** During an upgrade, the above changes might be overwritten. After the upgrade, follow the above procedure again.

### Workaround Procedure for R82.10

Show / Hide this section  
R82.10 upgraded the bash version and removed the bash_logger patch from previous versions.

In R82.10, Bash logging to */var/log/messages* does not occur after you follow the procedure outlined in this article until installing a hotfix or Jumbo HFA T36 or above.

To resolve this issue, [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue. After installing the hotfix, follow the procedure for previous versions to configure bash logging.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it. For faster resolution and verification, collect these files:

1. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member / Security Group involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
