5.3.11 Collect Login and Logout Events '/var/log/btmp'

Information

Configuration Level : Level-II

Solution

Add the following lines to the /etc/audit/audit.rules file.
-w /var/log/faillog -p wa -k logins
-w /var/log/lastlog -p wa -k logins
-w /var/log/tallylog -p wa -k logins
-w /var/log/btmp -p wa -k session
Execute the following command to restart auditd
pkill -P 1-HUP auditd

See Also

https://workbench.cisecurity.org/files/214

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12, CCE|CCE-14904-7

Plugin: Unix

Control ID: 4696d707a2b7c6b20e20a5158ff9ea30ea664c842d9d72d46d94689f32c34e3a