Use the event.execution.monitor parameter to monitor all programs that users run in an audited session.

To use this parameter, you must have enabled the agent to perform advanced monitoring with the command dacontrol -m.

The default value for the event.execution.monitor parameter is false.

In the audit.log file, you can find these events by looking for the cda_sys_execve messages. In the cdc.log file you can find them by looking for the Emit COMMAND_HISTORY.