4.1.2.11 Ensure off-load of audit logs.

Information

The operating system must configure the au-remote plugin to off-load audit logs using the audisp-remote daemon.

Information stored in one location is vulnerable to accidental or incidental deletion or alteration.

Off-loading is a common process in information systems with limited audit storage capacity.

Without the configuration of the "au-remote" plugin, the audisp-remote daemon will not off load the logs from the system being audited.

Solution

Edit the /etc/audisp/plugins.d/au-remote.conf file and add, uncomment or update the following values:

Example: vim /etc/audisp/plugins.d/au-remote.conf

Add uncomment or update the following lines:

direction = out
path = /sbin/audisp-remote
type = always

The audit daemon must be restarted for changes to take effect:

# service auditd restart

See Also

https://workbench.cisecurity.org/benchmarks/8415

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-2, 800-53|AU-7, 800-53|AU-12, CSCv7|6.2

Plugin: Unix

Control ID: a323fb648d6f184dfa36421359e028b901a12a7f02bb71df8cbff6f64e8270ba