APPL-14-004050 - The macOS system must configure install.log retention to 365.

Information

The install.log must be configured to require records be kept for an organizational-defined value before deletion, unless the system uses a central audit record storage facility.

Solution

Configure the macOS system with install.log retention to 365 with the following command:

/usr/bin/sed -i '' 's/* file /var/log/install.log.*/* file /var/log/install.log format='$((Time)(JZ)) $Host $(Sender)[$(PID\)]: $Message' rotate=utc compress file_max=50M size_only ttl=365/g' /etc/asl/com.apple.install

Note: If there are multiple configuration files in /etc/asl that are set to process the file /var/log/install.log, these files will have to be manually removed.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apple_macOS_14_V2R1_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4, CAT|III, CCI|CCI-001849, Rule-ID|SV-259558r958752_rule, STIG-ID|APPL-14-004050, Vuln-ID|V-259558

Plugin: Unix

Control ID: dc966f1ae45281c9a8dbd58a937ce767ebe8324d7e59bbfdf761b766a2992e9f