APPL-15-004050 - The macOS system must configure install.log retention to 365.

Information

The install.log must be configured to require that records be kept for an organizational-defined value before deletion, unless the system uses a central audit record storage facility.

Proper audit storage capacity is crucial to ensuring the ongoing logging of critical events.

Solution

Configure the macOS system with install.log retention to 365 with the following command:

/usr/bin/sed -i '' 's/* file /var/log/install.log.*/* file /var/log/install.log format='$((Time)(JZ)) $Host $(Sender)[$(PID\)]: $Message' rotate=utc compress file_max=50M size_only ttl=365/g' /etc/asl/com.apple.install

NOTE: If multiple configuration files in /etc/asl are set to process the file /var/log/install.log, these files must be manually removed.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apple_macOS_15_V1R1_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4, CAT|III, CCI|CCI-001849, Rule-ID|SV-268554r1034602_rule, STIG-ID|APPL-15-004050, Vuln-ID|V-268554

Plugin: Unix

Control ID: 6f3ccb6ac3bf19eee5756c1d0c4dccfe7813945aa198726be259fac0b1c37e42