I’ve been doing a lot of work recently setting up auditing of Splunk. One of the components of this is ingesting bash history, as most Splunk config changes are made from the command line. I found this great blog post by Duanne Waddle that explains how to enhance and capture bash history, which saved me a