5.2.3.6 Ensure login and logout events are collected

Information

Monitor login and logout events.

Monitoring login/logout events could provide a system administrator with information associated with brute-force attacks against user logins.

Solution

Edit the file /etc/security/audit_control, with the relevant rules to monitor events like login/logout.

Modify the flags directive to match the following:

flags:lo

This flag should be added if there were other flags previously configured rather than replacing the entire line.

See Also

https://workbench.cisecurity.org/benchmarks/19044