AZLX-23-001035 - Amazon Linux 2023 audispd-plugins package must be installed.

Information

The "audispd-plugins" package provides plugins for the real-time interface to the audit subsystem, "audispd". These plugins can, for example, relay events to remote machines or analyze events for suspicious behavior.

Solution

Configure Amazon Linux 2023 to have the audispd-plugins package installed.

Install the audispd-plugins package with the following command:

$ sudo dnf install -y audispd-plugins

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Amazon_Linux_2023_V1R2_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4(1), CAT|II, CCI|CCI-001851, Rule-ID|SV-274019r1120045_rule, STIG-ID|AZLX-23-001035, Vuln-ID|V-274019

Plugin: Unix

Control ID: e18805a93509622e34fb85114a1f5b2e233849be8769893d2cc6abd734d47618