1.384 RHEL-09-653095

Information

RHEL 9 must periodically flush audit records to disk to prevent the loss of audit records.

GROUP ID: V-258168
RULE ID: SV-258168r958428

If option "freq" is not set to a value that requires audit records being written to disk after a threshold number is reached, then audit records may be lost.

Solution

Configure RHEL 9 to flush audit to disk by adding or updating the following rule in "/etc/audit/auditd.conf":

freq = 100

The audit daemon must be restarted for the changes to take effect.

See Also

https://workbench.cisecurity.org/benchmarks/22008

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-6, 800-53|AU-6(4), CAT|II, CCI|CCI-000154, Rule-ID|SV-258168r958428_rule, STIG-ID|RHEL-09-653095, Vuln-ID|V-258168

Plugin: Unix

Control ID: cf785fd68aad436c8e75ca36ae096c1ebed1b5a929b51b0d73ea0d79f4d2338d