export HISTTIMEFORMAT="%d/%m/%y %T "
to your .bashrc and then history
will show the date and time before each command that was run. export HISTTIMEFORMAT="%d/%m/%y %T "
to your .bashrc and then history
will show the date and time before each command that was run.When I last needed it ~2011, there was a small and simple tool called libsnoopy for that.
Emphasis on "log file" though, the "history file" is a different use case, fundamentally unfit for forensics.
1) It made the history command run much, much slower (I have HISTSIZE=100000)
2) Dates tend to reset to a uniform but meaningless value. I think it's related to OS reboots.
My preference is just for a date in the history, rather than date and time. I find that when I'm searching history, date is usually granular enough for me, so I can omit the time and save a little bit of screen real estate.
With an updating prompt, you can see when a command ran without having to type 'history'.
And adding a date/time stamp to history is very useful when you need to go back further - hours, days or months.