dash.cmd.audit.show.actual.user
This configuration parameter specifies whether command-based auditing records will display the actual user account used to run a privileged command that requires auditing, as well as the run-as account.
By default, the value of this parameter is set to false, and only the run-as account used to execute privileged commands is shown in auditing records. To enable this parameter, set the value to true. For example:
dash.cmd.audit.show.actual.user: true