Check: RHEL-09-653105
RHEL 9 STIG:
RHEL-09-653105
(in versions v1 r3 through v1 r1)
Title
RHEL 9 must write audit records to disk. (Cat II impact)
Discussion
Audit data should be synchronously written to disk to ensure log integrity. This setting assures that all audit event data is written disk.
Check Content
Verify that the audit system is configured to write logs to the disk with the following command: $ sudo grep write_logs /etc/audit/auditd.conf write_logs = yes If "write_logs" does not have a value of "yes", the line is commented out, or the line is missing, this is a finding.
Fix Text
Configure the audit system to write log files to the disk. Edit the /etc/audit/auditd.conf file and add or update the "write_logs" option to "yes": write_logs = yes The audit daemon must be restarted for changes to take effect.
Additional Identifiers
Rule ID: SV-258170r926497_rule
Vulnerability ID: V-258170
Group Title: SRG-OS-000480-GPOS-00227
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |