4.1.8 Ensure login and logout events are collected - /var/log/lastlog

Information

Monitoring login/logout events could provide a system administrator with information associated with brute force attacks against user logins.

Solution

Add the following lines to the /etc/audit/audit.rules file:
-w /var/log/lastlog -p wa -k logins
-w /var/run/faillock/ -p wa -k logins

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12, CSCv6|5.5, CSCv6|16.4, CSCv6|16.10

Plugin: Unix

Control ID: 66005a08c6ae3d299d5e97fa225b4898127905c21b3779cac6272d2e1b08153d