STIGQter STIGQter: STIG Summary: SUSE Linux Enterprise Server 15 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 23 Apr 2021:

Audispd must off-load audit records onto a different system or media from the SUSE operating system being audited.

DISA Rule

SV-234968r622137_rule

Vulnerability Number

V-234968

Group Title

SRG-OS-000342-GPOS-00133

Rule Version

SLES-15-030690

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure the SUSE operating system "/etc/audisp/audisp-remote.conf" file to off-load audit records onto a different system or media by adding or editing the following line with the correct IP address:

remote_server = [IP ADDRESS]

Check Contents

Verify "audispd" off-loads audit records onto a different system or media from the SUSE operating system being audited.

Check if "audispd" is configured to off-load audit records onto a different system or media from the SUSE operating system by running the following command:

> sudo grep remote_server /etc/audisp/audisp-remote.conf
remote_server = 192.168.1.101

If "remote_server" is not set to an external server or media, or is commented out, this is a finding.

Vulnerability Number

V-234968

Documentable

False

Rule Version

SLES-15-030690

Severity Override Guidance

Verify "audispd" off-loads audit records onto a different system or media from the SUSE operating system being audited.

Check if "audispd" is configured to off-load audit records onto a different system or media from the SUSE operating system by running the following command:

> sudo grep remote_server /etc/audisp/audisp-remote.conf
remote_server = 192.168.1.101

If "remote_server" is not set to an external server or media, or is commented out, this is a finding.

Check Content Reference

M

Target Key

5274

Comments