4.7 (L1) Host must configure a persistent log location for all locally stored audit records

Information

Configuring a persistent log location for locally stored audit records on ESXi hosts is critical to ensure audit continuity. When the "/scratch" directory is linked to "/tmp/scratch", only a day's worth of records are retained, and they are reinitialized upon each reboot, creating a security risk. A persistent datastore, except a vSAN datastore, should be designated for audit record logging to preserve records across reboots. The parameter governing this behavior is Syslog.global.auditRecord.storageDirectory.

A persistent log location safeguards audit records, enhancing the auditability and diagnosability of system events. This setup helps in adhering to compliance requirements and facilitating future audits.

Solution

Impact:

Implementing this control will consume additional storage space for logs, necessitating a balanced approach to storage management, especially when local non-vSAN storage options are limited.

See Also

https://workbench.cisecurity.org/benchmarks/15784

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-6(3), CSCv7|6.5

Plugin: VMware

Control ID: 93479801de5d2f75954025672e4b385399b4aa128c1085e822e6bca412ec8666