3.200 - The system must be configured to use the au-remote plugin.

Information

Information stored in one location is vulnerable to accidental or incidental deletion or alteration.

Off-loading is a common process in information systems with limited audit storage capacity.

Without the configuration of the 'au-remote' plugin, the audisp-remote daemon will not off-load the logs from the system being audited.

Satisfies: SRG-OS-000342-GPOS-00133, SRG-OS-000479-GPOS-00224

Solution

Edit the /etc/audisp/plugins.d/au-remote.conf file and change the value of 'active' to 'yes'.

The audit daemon must be restarted for changes to take effect:

# service auditd restart

See Also

https://docs.fedoraproject.org/f28/system-administrators-guide/index.html

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4(1), CAT|II, CCI|CCI-001851

Plugin: Unix

Control ID: 3a8ef796440c7df0cd57d2727063883cba090fe32a81fe8abb6d8b3f748b1ebd