SV-239083r675057_rule
V-239083
SRG-OS-000038-GPOS-00016
PHTN-67-000011
CAT II
10
Open /etc/audit/auditd.conf with a text editor.
Ensure that the "log_format" line is uncommented and set to the following:
log_format = RAW
At the command line, execute the following command:
# service auditd reload
At the command line, execute the following command:
# grep "^log_format" /etc/audit/auditd.conf
Expected result:
log_format = RAW
If there is no output, this is not a finding.
If the output does not match the expected result, this is a finding.
V-239083
False
PHTN-67-000011
At the command line, execute the following command:
# grep "^log_format" /etc/audit/auditd.conf
Expected result:
log_format = RAW
If there is no output, this is not a finding.
If the output does not match the expected result, this is a finding.
M
5323