4.1.1.4 Ensure audit logs are stored on a different system.

Information

The operating system must off-load audit records onto a different system or media from the system being audited.

Rationale:

Information stored in one location is vulnerable to accidental or incidental deletion or alteration.

Off-loading is a common process in information systems with limited audit storage capacity.

Solution

Configure the operating system to off-load audit records onto a different system or media from the system being audited.
Set the remote server option in /etc/audisp/audisp-remote.conf with the IP address of the log aggregation server.
Example: vim /etc/audisp/audisp-remote.conf
Add, uncomment or update the following line:
Note: The ip address listed is just for an example. Replace it with the IP address or the log aggregation server in your environment.

remote_server = 10.0.21.1

Notes:

This Benchmark recommendation maps to:

Red Hat Enterprise Linux 7 Security Technical Implementation Guide:

Version 2, Release: 3 Benchmark Date: 26 Apr 2019



Vul ID: V-72083

Rule ID: SV-86707r2_rule

STIG ID: RHEL-07-030300

Severity: CAT II

See Also

https://workbench.cisecurity.org/files/2688

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-9(2)

Plugin: Unix

Control ID: 47500f7d2e91ce5b0a4d453f161836e962ab22ffbdf2d9c29539c1591e6b1d67