必须允许/var/log/.*
普通用户阅读日志。我按照文档做。本手册
mkdir -p /etc/sudoers.d/
visudo -f /etc/sudoers.d/mikelogger
在 visudo 里面
mikelogger localhost.localdomain = /usr/bin/tail /var/log/messages
跑
su mikelogger -
tail -f /var/log/messages
tail: cannot open '/var/log/messages' for reading: Permission denied
tail: no files remaining