Audits
Settings
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Theme
Light
Dark
Auto
Help
Plugins
Overview
Plugins Pipeline
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
Tenable OT Security Families
About Plugin Families
Release Notes
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
Release Notes
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Settings
Theme
Light
Dark
Auto
Detections
Plugins
Overview
Plugins Pipeline
Release Notes
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
Tenable OT Security Families
About Plugin Families
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
Release Notes
Analytics
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Audits
References
CCI
CCI-001851
CCI
CCI|CCI-001851
Title
Transfer audit logs per organization-defined frequency to a different system, system component, or media than the system or system component conducting the logging.
Reference Item Details
Reference:
CCI - DISA Control Correlation Identifier
Category:
2024
Audit Items
View all Reference Audit Items
Name
Plugin
Audit Name
1.15 UBTU-24-100450
Unix
CIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT III
1.116 UBTU-22-651035
Unix
CIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT III
1.121 UBTU-22-653020
Unix
CIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT III
1.174 UBTU-24-900950
Unix
CIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT III
1.212 OL08-00-030062
Unix
CIS Oracle Linux 8 STIG v1.0.0 CAT II
1.278 OL08-00-030690
Unix
CIS Oracle Linux 8 STIG v1.0.0 CAT II
1.279 OL08-00-030700
Unix
CIS Oracle Linux 8 STIG v1.0.0 CAT II
1.280 OL08-00-030710
Unix
CIS Oracle Linux 8 STIG v1.0.0 CAT II
1.281 OL08-00-030720
Unix
CIS Oracle Linux 8 STIG v1.0.0 CAT II
1.357 RHEL-09-652010
Unix
CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.362 RHEL-09-652040
Unix
CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.363 RHEL-09-652045
Unix
CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.364 RHEL-09-652050
Unix
CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.365 RHEL-09-652055
Unix
CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.371 RHEL-09-653030
Unix
CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.377 RHEL-09-653060
Unix
CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.378 RHEL-09-653065
Unix
CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.391 RHEL-09-653130
Unix
CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
4.1.2.3 Ensure audit system is set to single when the disk is full.
Unix
CIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
4.1.2.6 Ensure audit system action is defined for sending errors
Unix
CIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
4.1.2.8 Ensure audit logs are stored on a different system.
Unix
CIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
4.1.2.9 Ensure audit logs on separate system are encrypted.
Unix
CIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
4.1.2.11 Ensure off-load of audit logs - direction
Unix
CIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
4.1.2.11 Ensure off-load of audit logs - path
Unix
CIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
4.1.2.11 Ensure off-load of audit logs - type
Unix
CIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
4.1.2.12 Ensure action is taken when audisp-remote buffer is full
Unix
CIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
4.1.2.13 Ensure off-loaded audit logs are labeled.
Unix
CIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
AIX7-00-002017 - AIX must be configured so that the audit system takes appropriate action when the audit storage volume is full.
Unix
DISA STIG AIX 7.x v3r1
AIX7-00-002131 - AIX must implement a remote syslog server that is documented using site-defined procedures.
Unix
DISA STIG AIX 7.x v3r1
ALMA-09-052160 - AlmaLinux OS 9 audispd-plugins package must be installed.
Unix
DISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-052270 - AlmaLinux OS 9 must label all offloaded audit logs before sending them to the central log server.
Unix
DISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-052380 - AlmaLinux OS 9 must take appropriate action when the internal event queue is full.
Unix
DISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-052490 - AlmaLinux OS 9 must be configured to offload audit records onto a different system from the system being audited via syslog.
Unix
DISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-052600 - AlmaLinux OS 9 must authenticate the remote logging server for offloading audit logs via rsyslog.
Unix
DISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-052710 - AlmaLinux OS 9 must encrypt the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog.
Unix
DISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-052820 - AlmaLinux OS 9 must encrypt, via the gtls driver, the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog.
Unix
DISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-052930 - AlmaLinux OS 9 must have the rsyslog package installed.
Unix
DISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-053040 - AlmaLinux OS 9 must be configured to forward audit records via TCP to a different system or media from the system being audited via rsyslog.
Unix
DISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-053150 - The rsyslog service on AlmaLinux OS 9 must be active.
Unix
DISA CloudLinux AlmaLinux OS 9 STIG v1r2
AMLS-NM-000400 - The Arista Multilayer Switch must, at a minimum, off-load audit records for interconnected systems in real time - logging host
Arista
DISA STIG Arista MLS DCS-7000 Series NDM v1r4
AMLS-NM-000400 - The Arista Multilayer Switch must, at a minimum, off-load audit records for interconnected systems in real time - trap logging
Arista
DISA STIG Arista MLS DCS-7000 Series NDM v1r4
ARST-ND-000850 - The Arista network Arista device must be configured to send log data to a central log server for the purpose of forwarding alerts to the administrators and the ISSO.
Arista
DISA STIG Arista MLS EOS 4.x NDM v2r2
ARST-ND-000850 - The Arista network Arista device must be configured to send log data to a central log server for the purpose of forwarding alerts to the administrators and the ISSO.
Arista
DISA STIG Arista MLS EOS 4.2x NDM v2r1
AS24-U1-000720 - The Apache web server must not impede the ability to write specified log record content to an audit log server.
Unix
DISA STIG Apache Server 2.4 Unix Server v3r2 Middleware
AS24-U1-000720 - The Apache web server must not impede the ability to write specified log record content to an audit log server.
Unix
DISA STIG Apache Server 2.4 Unix Server v3r2
AS24-U1-000730 - The Apache web server must be configured to integrate with an organizations security infrastructure.
Unix
DISA STIG Apache Server 2.4 Unix Server v3r2
AS24-U1-000730 - The Apache web server must be configured to integrate with an organizations security infrastructure.
Unix
DISA STIG Apache Server 2.4 Unix Server v3r2 Middleware
AS24-W1-000720 - The Apache web server must not impede the ability to write specified log record content to an audit log server.
Windows
DISA STIG Apache Server 2.4 Windows Server v3r3
AS24-W1-000720 - The Apache web server must not impede the ability to write specified log record content to an audit log server.
Windows
DISA STIG Apache Server 2.4 Windows Server v2r3
AS24-W1-000730 - The Apache web server must be configurable to integrate with an organizations security infrastructure.
Windows
DISA STIG Apache Server 2.4 Windows Server v3r3