5.3.11 Collect Login and Logout Events '/var/log/lastlog'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Configuration Level : Level-II

Solution

Add the following lines to the /etc/audit/audit.rules file.
-w /var/log/faillog -p wa -k logins
-w /var/log/lastlog -p wa -k logins
-w /var/log/tallylog -p wa -k logins
-w /var/log/btmp -p wa -k session
Execute the following command to restart auditd
pkill -P 1-HUP auditd

See Also

https://workbench.cisecurity.org/files/214

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12, CCE|CCE-14904-7

Plugin: Unix

Control ID: a5286ab60db9b850bc860bcbf3678bf40eff8922fbe2d00b070930cf19a91c41