SV-230394r627750_rule
V-230394
SRG-OS-000342-GPOS-00133
RHEL-08-030062
CAT II
10
Edit the /etc/audit/auditd.conf file and add or update the "name_format" option:
name_format = hostname
The audit daemon must be restarted for changes to take effect.
Verify the RHEL 8 Audit Daemon is configured to label all off-loaded audit logs, with the following command:
$ sudo grep "name_format" /etc/audit/auditd.conf
name_format = hostname
If the "name_format" option is not "hostname", "fqd", or "numeric", or the line is commented out, this is a finding.
V-230394
False
RHEL-08-030062
Verify the RHEL 8 Audit Daemon is configured to label all off-loaded audit logs, with the following command:
$ sudo grep "name_format" /etc/audit/auditd.conf
name_format = hostname
If the "name_format" option is not "hostname", "fqd", or "numeric", or the line is commented out, this is a finding.
M
2921