5.3.11 Collect Login and Logout Events '/var/log/tallylog'

Information

Configuration Level : Level-II

Solution

Add the following lines to the /etc/audit/audit.rules file.
-w /var/log/faillog -p wa -k logins
-w /var/log/lastlog -p wa -k logins
-w /var/log/tallylog -p wa -k logins
-w /var/log/btmp -p wa -k session
Execute the following command to restart auditd
pkill -P 1-HUP auditd

See Also

https://workbench.cisecurity.org/files/214

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12, CCE|CCE-14904-7

Plugin: Unix

Control ID: 7fc58857f4f02e195e063261c8c1dfb3b309ab5703c4414ab919b9fe6d965345