4.1.8 Ensure login and logout events are collected - lastlog

Information

Monitor login and logout events. The parameters below track changes to files associated with login/logout events. The file /var/log/lastlog maintain records of the last time a user successfully logged in. The /var/run/failock directory maintains records of login failures via the pam_faillock module. Monitoring login/logout events could provide a system administrator with information associated with brute force attacks against user logins.

Solution

Add the following lines to the /etc/audit/audit.rules file: -w /var/log/lastlog -p wa -k logins-w /var/run/faillock/ -p wa -k logins

See Also

https://benchmarks.cisecurity.org/tools2/linux/CIS_SUSE_Linux_Enterprise_11_Benchmark_v2.0.0.pdf

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12

Plugin: Unix

Control ID: fe8e70f210958bbe1ade00a7281cc6144cd4244a9d3627a46e13259f8446cd4e