SV-230393r627750_rule
V-230393
SRG-OS-000480-GPOS-00227
RHEL-08-030061
CAT II
10
Configure RHEL 8 to audit local events on the system.
Add or update the following line in "/etc/audit/auditd.conf" file:
local_events = yes
Verify the RHEL 8 Audit Daemon is configured to include local events, with the following command:
$ sudo grep local_events /etc/audit/auditd.conf
local_events = yes
If the value of the "local_events" option is not set to "yes", or the line is commented out, this is a finding.
V-230393
False
RHEL-08-030061
Verify the RHEL 8 Audit Daemon is configured to include local events, with the following command:
$ sudo grep local_events /etc/audit/auditd.conf
local_events = yes
If the value of the "local_events" option is not set to "yes", or the line is commented out, this is a finding.
M
2921