SV-227810r603266_rule
V-227810
SRG-OS-000062
GEN003660
CAT II
10
Edit /etc/syslog.conf and add local log destinations for auth.* or both auth.notice and auth.info.
Check /etc/syslog.conf and verify the auth facility is logging both the notice and info level messages by using one of the procedures below.
# grep "auth.notice" /etc/syslog.conf
# grep "auth.info" /etc/syslog.conf
OR
# grep 'auth.*' /etc/syslog.conf
If auth.* is not found, and either auth.notice or auth.info is not found, this is a finding.
V-227810
False
GEN003660
Check /etc/syslog.conf and verify the auth facility is logging both the notice and info level messages by using one of the procedures below.
# grep "auth.notice" /etc/syslog.conf
# grep "auth.info" /etc/syslog.conf
OR
# grep 'auth.*' /etc/syslog.conf
If auth.* is not found, and either auth.notice or auth.info is not found, this is a finding.
M
4061