Item Search

NameAudit NamePluginCategory
4.1.2.3 Ensure audit system is set to single when the disk is full.CIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

AUDIT AND ACCOUNTABILITY

4.1.2.6 Ensure audit system action is defined for sending errorsCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

AUDIT AND ACCOUNTABILITY

4.1.2.8 Ensure audit logs are stored on a different system.CIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

AUDIT AND ACCOUNTABILITY

4.1.2.9 Ensure audit logs on separate system are encrypted.CIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

AUDIT AND ACCOUNTABILITY

4.1.2.11 Ensure off-load of audit logs - directionCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

AUDIT AND ACCOUNTABILITY

4.1.2.11 Ensure off-load of audit logs - pathCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

AUDIT AND ACCOUNTABILITY

4.1.2.11 Ensure off-load of audit logs - typeCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

AUDIT AND ACCOUNTABILITY

4.1.2.12 Ensure action is taken when audisp-remote buffer is fullCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

AUDIT AND ACCOUNTABILITY

4.1.2.13 Ensure off-loaded audit logs are labeled.CIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

AUDIT AND ACCOUNTABILITY

Big Sur - Off-Load Audit RecordsNIST macOS Big Sur v1.4.0 - All ProfilesUnix

AUDIT AND ACCOUNTABILITY

CASA-ND-001260 - The Cisco ASA must be configured to offload audit records onto a different system or media than the system being audited - logging trapDISA STIG Cisco ASA NDM v2r1Cisco

AUDIT AND ACCOUNTABILITY

CASA-ND-001410 - The Cisco ASA must be configured to send log data to at least two central log servers for the purpose of forwarding alerts to organization-defined personnel and/or the firewall administrator - logging hostDISA STIG Cisco ASA NDM v2r1Cisco

AUDIT AND ACCOUNTABILITY

Catalina - Off-Load Audit RecordsNIST macOS Catalina v1.5.0 - All ProfilesUnix

AUDIT AND ACCOUNTABILITY

CD12-00-011300 - PostgreSQL must off-load audit data to a separate log management facility; this must be continuous and in near real time for systems with a network connection to the storage facility and weekly or more often for stand-alone systems.DISA STIG Crunchy Data PostgreSQL DB v3r1PostgreSQLDB

AUDIT AND ACCOUNTABILITY

EPAS-00-013000 - The EDB Postgres Advanced Server must off-load audit data to a separate log management facility; this must be continuous and in near real time for systems with a network connection to the storage facility and weekly or more often for stand-alone systems.EnterpriseDB PostgreSQL Advanced Server DB v2r1PostgreSQLDB

AUDIT AND ACCOUNTABILITY

FNFG-FW-000100 - The FortiGate firewall must send traffic log entries to a central audit server for management and configuration of the traffic log entries.DISA Fortigate Firewall STIG v1r3FortiGate

AUDIT AND ACCOUNTABILITY

JUEX-NM-000600 - The Juniper EX switch must be configured to offload audit records onto a different system or media than the system being audited.DISA Juniper EX Series Network Device Management v2r1Juniper

AUDIT AND ACCOUNTABILITY

MADB-10-012400 - MariaDB must off-load audit data to a separate log management facility; this must be continuous and in near real time for systems with a network connection to the storage facility and weekly or more often for stand-alone systems.DISA MariaDB Enterprise 10.x v2r1 DBMySQLDB

AUDIT AND ACCOUNTABILITY

Monterey - Off-Load Audit RecordsNIST macOS Monterey v1.0.0 - All ProfilesUnix

AUDIT AND ACCOUNTABILITY

MYS8-00-009700 - The MySQL Database Server 8.0 must off-load audit data to a separate log management facility; this must be continuous and in near real time for systems with a network connection to the storage facility and weekly or more often for stand-alone systems.DISA Oracle MySQL 8.0 v2r1 DBMySQLDB

AUDIT AND ACCOUNTABILITY

OL08-00-030062 - OL 8 must label all offloaded audit logs before sending them to the central log server.DISA Oracle Linux 8 STIG v2r1Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030690 - The OL 8 audit records must be offloaded onto a different system or storage media from the system being audited.DISA Oracle Linux 8 STIG v2r1Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030700 - OL 8 must take appropriate action when the internal event queue is full.DISA Oracle Linux 8 STIG v2r1Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030720 - OL 8 must authenticate the remote logging server for offloading audit logs.DISA Oracle Linux 8 STIG v2r1Unix

AUDIT AND ACCOUNTABILITY

RHEL-08-030062 - RHEL 8 must label all off-loaded audit logs before sending them to the central log server.DISA Red Hat Enterprise Linux 8 STIG v2r1Unix

AUDIT AND ACCOUNTABILITY

RHEL-08-030690 - The RHEL 8 audit records must be off-loaded onto a different system or storage media from the system being audited.DISA Red Hat Enterprise Linux 8 STIG v2r1Unix

AUDIT AND ACCOUNTABILITY

RHEL-08-030700 - RHEL 8 must take appropriate action when the internal event queue is full.DISA Red Hat Enterprise Linux 8 STIG v2r1Unix

AUDIT AND ACCOUNTABILITY

RHEL-08-030710 - RHEL 8 must encrypt the transfer of audit records off-loaded onto a different system or media from the system being audited.DISA Red Hat Enterprise Linux 8 STIG v2r1Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-652040 - RHEL 9 must authenticate the remote logging server for offloading audit logs via rsyslog.DISA Red Hat Enterprise Linux 9 STIG v2r2Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-653065 - RHEL 9 must take appropriate action when the internal event queue is full.DISA Red Hat Enterprise Linux 9 STIG v2r2Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-653130 - RHEL 9 audispd-plugins package must be installed.DISA Red Hat Enterprise Linux 9 STIG v2r2Unix

AUDIT AND ACCOUNTABILITY

SLES-15-010580 - The SUSE operating system must off-load rsyslog messages for networked systems in real time and off-load standalone systems at least weekly.DISA SLES 15 STIG v2r1Unix

AUDIT AND ACCOUNTABILITY

SLES-15-030670 - The audit-audispd-plugins must be installed on the SUSE operating system.DISA SLES 15 STIG v2r1Unix

AUDIT AND ACCOUNTABILITY

SPLK-CL-000150 - Splunk Enterprise must be configured to offload log records onto a different system or media than the system being audited.DISA STIG Splunk Enterprise 8.x for Linux v2r1 STIG REST APISplunk

AUDIT AND ACCOUNTABILITY

SYMP-AG-000220 - Symantec ProxySG must be configured to send the access logs to the centralized log server continuously.DISA Symantec ProxySG Benchmark ALG v1r3BlueCoat

AUDIT AND ACCOUNTABILITY

SYMP-NM-000080 - Symantec ProxySG must be configured to support centralized management and configuration of the audit log - enableDISA Symantec ProxySG Benchmark NDM v1r2BlueCoat

AUDIT AND ACCOUNTABILITY

SYMP-NM-000080 - Symantec ProxySG must be configured to support centralized management and configuration of the audit log - Syslog IPDISA Symantec ProxySG Benchmark NDM v1r2BlueCoat

AUDIT AND ACCOUNTABILITY

UBTU-20-010216 - The Ubuntu operating system audit event multiplexor must be configured to off-load audit logs onto a different system or storage media from the system being audited.DISA STIG Ubuntu 20.04 LTS v2r1Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-651035 - Ubuntu 22.04 LTS must have a crontab script running weekly to offload audit events of standalone systems.DISA STIG Canonical Ubuntu 22.04 LTS v2r2Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-653020 - Ubuntu 22.04 LTS audit event multiplexor must be configured to offload audit logs onto a different system from the system being audited.DISA STIG Canonical Ubuntu 22.04 LTS v2r2Unix

AUDIT AND ACCOUNTABILITY

VCFL-67-000027 - Rsyslog must be configured to monitor and ship vSphere Client log files - accessDISA STIG VMware vSphere 6.7 Virgo Client v1r2Unix

AUDIT AND ACCOUNTABILITY

VCFL-67-000027 - Rsyslog must be configured to monitor and ship vSphere Client log files - runtimeDISA STIG VMware vSphere 6.7 Virgo Client v1r2Unix

AUDIT AND ACCOUNTABILITY

VCLU-80-000081 The vCenter Lookup service must offload log records onto a different system or media from the system being logged.DISA VMware vSphere 8.0 vCenter Appliance Lookup Service STIG v2r1Unix

AUDIT AND ACCOUNTABILITY

VCPF-80-000081 The vCenter Perfcharts service must offload log records onto a different system or media from the system being logged.DISA VMware vSphere 8.0 vCenter Appliance Perfcharts STIG v2r1Unix

AUDIT AND ACCOUNTABILITY

VCRP-67-000009 - The rhttpproxy log files must be moved to a permanent repository in accordance with site policy.DISA STIG VMware vSphere 6.7 RhttpProxy v1r3Unix

AUDIT AND ACCOUNTABILITY

VCRP-70-000008 - Envoy log files must be shipped via syslog to a central log serverDISA STIG VMware vSphere 7.0 RhttpProxy v1r1Unix

AUDIT AND ACCOUNTABILITY

VCST-80-000081 The vCenter STS service must offload log records onto a different system or media from the system being logged.DISA VMware vSphere 8.0 vCenter Appliance Secure Token Service (STS) STIG v2r1Unix

AUDIT AND ACCOUNTABILITY

VCUI-80-000081 The vCenter UI service must offload log records onto a different system or media from the system being logged.DISA VMware vSphere 8.0 vCenter Appliance User Interface (UI) STIG v2r1Unix

AUDIT AND ACCOUNTABILITY

WN22-AU-000010 - Windows Server 2022 audit records must be backed up to a different system or media than the system being audited.DISA Windows Server 2022 STIG v2r2Windows

AUDIT AND ACCOUNTABILITY

WN22-AU-000020 - Windows Server 2022 must, at a minimum, offload audit records of interconnected systems in real time and offload standalone or nondomain-joined systems weekly.DISA Windows Server 2022 STIG v2r2Windows

AUDIT AND ACCOUNTABILITY