SV-227577r603266_rule
V-227577
SRG-OS-000470
GEN000440
CAT II
10
Verify that login logs are handled correctly in the /etc/syslog.conf file. Edit the /etc/syslog.conf file and add one of the entries below.
auth.debug /var/log/authlog
OR
auth.* /var/log/authlog
Verify that service startup scripts for syslog and utmp (if present) are enabled.
Determine if successful logons are being logged.
# last | more
Determine if unsuccessful logons are being logged.
# more /var/adm/loginlog
If the commands do not return successful and unsuccessful logins, this is a finding.
Check the syslog daemon configuration for authentication logging.
# egrep "auth\.(info|debug)" /etc/syslog.conf
If there are no entries in syslog for the auth service, this is a finding.
V-227577
False
GEN000440
Determine if successful logons are being logged.
# last | more
Determine if unsuccessful logons are being logged.
# more /var/adm/loginlog
If the commands do not return successful and unsuccessful logins, this is a finding.
Check the syslog daemon configuration for authentication logging.
# egrep "auth\.(info|debug)" /etc/syslog.conf
If there are no entries in syslog for the auth service, this is a finding.
M
4061