Item Search

NameAudit NamePluginCategory
CASA-ND-001260 - The Cisco ASA must be configured to offload audit records onto a different system or media than the system being audited - logging hostDISA STIG Cisco ASA NDM v1r1Cisco
CASA-ND-001260 - The Cisco ASA must be configured to offload audit records onto a different system or media than the system being audited - logging trapDISA STIG Cisco ASA NDM v1r6Cisco
CASA-ND-001410 - The Cisco ASA must be configured to send log data to a central log server for the purpose of forwarding alerts to organization-defined personnel and/or the firewall administrator - logging hostDISA STIG Cisco ASA NDM v1r3Cisco
CASA-ND-001410 - The Cisco ASA must be configured to send log data to a central log server for the purpose of forwarding alerts to organization-defined personnel and/or the firewall administrator - logging trapDISA STIG Cisco ASA NDM v1r3Cisco
CISC-ND-001310 - The Cisco switch must be configured to off-load log records onto a different system than the system being audited - logging hostDISA STIG Cisco IOS XE Switch NDM v1r1Cisco
FGFW-ND-000110 - The FortiGate device must off-load audit records on to a different system or media than the system being audited.DISA Fortigate Firewall NDM STIG v1r1FortiGate
FGFW-ND-000110 - The FortiGate device must off-load audit records on to a different system or media than the system being audited.DISA Fortigate Firewall NDM STIG v1r3FortiGate
JUEX-NM-000600 - The Juniper EX switch must be configured to offload audit records onto a different system or media than the system being audited.DISA Juniper EX Series Network Device Management v1r5Juniper
JUEX-NM-000600 - The Juniper EX switch must be configured to offload audit records onto a different system or media than the system being audited.DISA Juniper EX Series Network Device Management v1r4Juniper
MADB-10-012400 - MariaDB must off-load audit data to a separate log management facility; this must be continuous and in near real time for systems with a network connection to the storage facility and weekly or more often for stand-alone systems.DISA MariaDB Enterprise 10.x v1r3 DBMySQLDB
MYS8-00-009700 - The MySQL Database Server 8.0 must off-load audit data to a separate log management facility; this must be continuous and in near real time for systems with a network connection to the storage facility and weekly or more often for stand-alone systems.DISA Oracle MySQL 8.0 v1r3 DBMySQLDB
OL08-00-030062 - OL 8 must label all offloaded audit logs before sending them to the central log server.DISA Oracle Linux 8 STIG v1r8Unix
OL08-00-030062 - OL 8 must label all offloaded audit logs before sending them to the central log server.DISA Oracle Linux 8 STIG v1r9Unix
OL08-00-030690 - The OL 8 audit records must be offloaded onto a different system or storage media from the system being audited.DISA Oracle Linux 8 STIG v1r1Unix
OL08-00-030690 - The OL 8 audit records must be offloaded onto a different system or storage media from the system being audited.DISA Oracle Linux 8 STIG v1r7Unix
OL08-00-030700 - OL 8 must take appropriate action when the internal event queue is full.DISA Oracle Linux 8 STIG v1r1Unix
OL08-00-030710 - OL 8 must encrypt the transfer of audit records offloaded onto a different system or media from the system being audited - DefaultNetstreamDriverDISA Oracle Linux 8 STIG v1r2Unix
RHEL-08-030062 - RHEL 8 must label all off-loaded audit logs before sending them to the central log server.DISA Red Hat Enterprise Linux 8 STIG v1r11Unix
RHEL-08-030690 - The RHEL 8 audit records must be off-loaded onto a different system or storage media from the system being audited.DISA Red Hat Enterprise Linux 8 STIG v1r13Unix
RHEL-08-030690 - The RHEL 8 audit records must be off-loaded onto a different system or storage media from the system being audited.DISA Red Hat Enterprise Linux 8 STIG v1r6Unix
RHEL-08-030690 - The RHEL 8 audit records must be off-loaded onto a different system or storage media from the system being audited.DISA Red Hat Enterprise Linux 8 STIG v1r7Unix
RHEL-08-030700 - RHEL 8 must take appropriate action when the internal event queue is full.DISA Red Hat Enterprise Linux 8 STIG v1r8Unix
RHEL-08-030700 - RHEL 8 must take appropriate action when the internal event queue is full.DISA Red Hat Enterprise Linux 8 STIG v1r1Unix
RHEL-08-030710 - RHEL 8 must encrypt the transfer of audit records off-loaded onto a different system or media from the system being audited - DefaultNetstreamDriverDISA Red Hat Enterprise Linux 8 STIG v1r9Unix
RHEL-08-030710 - RHEL 8 must encrypt the transfer of audit records off-loaded onto a different system or media from the system being audited.DISA Red Hat Enterprise Linux 8 STIG v1r13Unix
RHEL-08-030710 - RHEL 8 must encrypt the transfer of audit records off-loaded onto a different system or media from the system being audited. - DefaultNetstreamDriverDISA Red Hat Enterprise Linux 8 STIG v1r1Unix
RHEL-08-030720 - RHEL 8 must authenticate the remote logging server for off-loading audit logs.DISA Red Hat Enterprise Linux 8 STIG v1r9Unix
RHEL-08-030720 - RHEL 8 must authenticate the remote logging server for off-loading audit logs.DISA Red Hat Enterprise Linux 8 STIG v1r11Unix
RHEL-09-652045 - RHEL 9 must encrypt the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog.DISA Red Hat Enterprise Linux 9 STIG v1r1Unix
RHEL-09-653130 - RHEL 9 audispd-plugins package must be installed.DISA Red Hat Enterprise Linux 9 STIG v1r1Unix
SLES-15-030670 - The audit-audispd-plugins must be installed on the SUSE operating system.DISA SLES 15 STIG v1r11Unix
SLES-15-030680 - The SUSE operating system audit event multiplexor must be configured to use Kerberos.DISA SLES 15 STIG v1r9Unix
SLES-15-030690 - Audispd must off-load audit records onto a different system or media from the SUSE operating system being audited.DISA SLES 15 STIG v1r6Unix
SLES-15-030690 - Audispd must off-load audit records onto a different system or media from the SUSE operating system being audited.DISA SLES 15 STIG v1r10Unix
SLES-15-030790 - The SUSE operating system must off-load audit records onto a different system or media from the system being audited.DISA SLES 15 STIG v1r13Unix
SLES-15-030800 - Audispd must take appropriate action when the SUSE operating system audit storage is full.DISA SLES 15 STIG v1r6Unix
SLES-15-030800 - Audispd must take appropriate action when the SUSE operating system audit storage is full.DISA SLES 15 STIG v1r11Unix
SLES-15-030800 - Audispd must take appropriate action when the SUSE operating system audit storage is full.DISA SLES 15 STIG v1r13Unix
SPLK-CL-000150 - Splunk Enterprise must be configured to offload log records onto a different system or media than the system being audited.DISA STIG Splunk Enterprise 8.x for Linux v1r4 STIG REST APISplunk
UBTU-20-010216 - The Ubuntu operating system audit event multiplexor must be configured to off-load audit logs onto a different system or storage media from the system being audited - active = yesDISA STIG Ubuntu 20.04 LTS v1r4Unix
UBTU-20-010216 - The Ubuntu operating system audit event multiplexor must be configured to off-load audit logs onto a different system or storage media from the system being audited - active = yesDISA STIG Ubuntu 20.04 LTS v1r5Unix
UBTU-20-010216 - The Ubuntu operating system audit event multiplexor must be configured to off-load audit logs onto a different system or storage media from the system being audited - active = yesDISA STIG Ubuntu 20.04 LTS v1r1Unix
UBTU-20-010216 - The Ubuntu operating system audit event multiplexor must be configured to off-load audit logs onto a different system or storage media from the system being audited - audispd-pluginsDISA STIG Ubuntu 20.04 LTS v1r4Unix
UBTU-20-010216 - The Ubuntu operating system audit event multiplexor must be configured to off-load audit logs onto a different system or storage media from the system being audited - audispd-pluginsDISA STIG Ubuntu 20.04 LTS v1r5Unix
UBTU-20-010216 - The Ubuntu operating system audit event multiplexor must be configured to off-load audit logs onto a different system or storage media from the system being audited - remote_serverDISA STIG Ubuntu 20.04 LTS v1r4Unix
UBTU-20-010216 - The Ubuntu operating system audit event multiplexor must be configured to off-load audit logs onto a different system or storage media from the system being audited - remote_serverDISA STIG Ubuntu 20.04 LTS v1r5Unix
UBTU-20-010300 - The Ubuntu operating system must have a crontab script running weekly to offload audit events of standalone systems.DISA STIG Ubuntu 20.04 LTS v1r4Unix
VCSA-70-000280 - The vCenter server must be configured to send events to a central log server.DISA STIG VMware vSphere 7.0 vCenter v1r2VMware
WN22-AU-000010 - Windows Server 2022 audit records must be backed up to a different system or media than the system being audited.DISA Windows Server 2022 STIG v1r4Windows
WN22-AU-000020 - Windows Server 2022 must, at a minimum, offload audit records of interconnected systems in real time and offload standalone or nondomain-joined systems weekly.DISA Windows Server 2022 STIG v1r3Windows