SV-204503r603261_rule
V-204503
SRG-OS-000038-GPOS-00016
RHEL-07-030000
CAT II
10
Configure the operating system to produce audit records containing information to establish when (date and time) the events occurred.
Enable the auditd service with the following command:
# systemctl start auditd.service
Verify the operating system produces audit records containing information to establish when (date and time) the events occurred.
Check to see if auditing is active by issuing the following command:
# systemctl is-active auditd.service
active
If the "auditd" status is not active, this is a finding.
V-204503
False
RHEL-07-030000
Verify the operating system produces audit records containing information to establish when (date and time) the events occurred.
Check to see if auditing is active by issuing the following command:
# systemctl is-active auditd.service
active
If the "auditd" status is not active, this is a finding.
M
2899