3.201 - The system must configure the au-remote plugin to off-load audit logs using the audisp-remote daemon - type

Information

Information stored in one location is vulnerable to accidental or incidental deletion or alteration.

Off-loading is a common process in information systems with limited audit storage capacity.

Without the configuration of the 'au-remote' plugin, the audisp-remote daemon will not off load the logs from the system being audited.

Satisfies: SRG-OS-000342-GPOS-00133, SRG-OS-000479-GPOS-00224

Solution

Edit the /etc/audisp/plugins.d/au-remote.conf file and add or update the following values:

direction = out
path = /sbin/audisp-remote
type = always

The audit daemon must be restarted for changes to take effect:

# service auditd restart

See Also

https://docs.fedoraproject.org/f28/system-administrators-guide/index.html

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4(1), CAT|II, CCI|CCI-001851

Plugin: Unix

Control ID: 0ed21d69c4f902528945be3b71625b1dbd79b50237e1b72cc38e71ac7cb8ec34