FireEye - Configuration auditing logs the required number of changes

Information

Saving past configurations allows them to be audited for unauthorized changes and reviewed when troubleshooting. Auditing cannot be disabled but can be set to 1, significantly reducing effectiveness. Configuration changes can be exported through the Log Manager.

Solution

The default value is 1000. Edit the configuration and add or modify this line:\n

configuration audit max-changes 1000

Item Details

Audit Name: TNS FireEye

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-3e.

Plugin: FireEye

Control ID: a5c9bf000e7d0f2fc4cb883918dbaa1afef90f9bbc5d21a0ee0289f15ff40c5e