PHTN-40-000186 The Photon operating system must ensure audit events are flushed to disk at proper intervals.

Information

Without the capability to generate audit records, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. To that end, the auditd service must be configured to start automatically and be running at all times.

Solution

Navigate to and open:

/etc/audit/auditd.conf

Add or update the following lines:

flush = INCREMENTAL_ASYNC
freq = 50

At the command line, run the following command:

# pkill -SIGHUP auditd

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_vSphere_8-0_Y24M08_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-258855r991589_rule, STIG-ID|PHTN-40-000186, Vuln-ID|V-258855

Plugin: Unix

Control ID: d508723345851a09cfca50fad9b8360d094727188cb42f4e386d1ba7691d63d8