SV-230477r627750_rule
V-230477
SRG-OS-000480-GPOS-00227
RHEL-08-030670
CAT II
10
Configure the operating system to offload audit logs by installing the required packages with the following command:
$ sudo yum install rsyslog
Verify the operating system has the packages required for offloading audit logs installed with the following commands:
$ sudo yum list installed rsyslog
rsyslog.x86_64 8.1911.0-3.el8 @AppStream
If the "rsyslog" package is not installed, ask the administrator to indicate how audit logs are being offloaded and what packages are installed to support it. If there is no evidence of audit logs being offloaded, this is a finding.
V-230477
False
RHEL-08-030670
Verify the operating system has the packages required for offloading audit logs installed with the following commands:
$ sudo yum list installed rsyslog
rsyslog.x86_64 8.1911.0-3.el8 @AppStream
If the "rsyslog" package is not installed, ask the administrator to indicate how audit logs are being offloaded and what packages are installed to support it. If there is no evidence of audit logs being offloaded, this is a finding.
M
2921