SV-230395r627750_rule
V-230395
SRG-OS-000480-GPOS-00227
RHEL-08-030063
CAT III
10
Edit the /etc/audit/auditd.conf file and add or update the "log_format" option:
log_format = ENRICHED
The audit daemon must be restarted for changes to take effect.
Verify the RHEL 8 Audit Daemon is configured to resolve audit information before writing to disk, with the following command:
$ sudo grep "log_format" /etc/audit/auditd.conf
log_format = ENRICHED
If the "log_format" option is not "ENRICHED", or the line is commented out, this is a finding.
V-230395
False
RHEL-08-030063
Verify the RHEL 8 Audit Daemon is configured to resolve audit information before writing to disk, with the following command:
$ sudo grep "log_format" /etc/audit/auditd.conf
log_format = ENRICHED
If the "log_format" option is not "ENRICHED", or the line is commented out, this is a finding.
M
2921