SV-239143r675237_rule
V-239143
SRG-OS-000470-GPOS-00214
PHTN-67-000072
CAT II
10
At the command line, execute the following commands:
# echo '-w /var/log/faillog -p wa' >> /etc/audit/rules.d/audit.STIG.rules
# echo '-w /var/log/lastlog -p wa' >> /etc/audit/rules.d/audit.STIG.rules
# echo '-w /var/log/tallylog -p wa' >> /etc/audit/rules.d/audit.STIG.rules
# /sbin/augenrules --load
At the command line, execute the following command:
# auditctl -l | grep -E "faillog|lastlog|tallylog"
Expected result:
-w /var/log/faillog -p wa
-w /var/log/lastlog -p wa
-w /var/log/tallylog -p wa
If the output does not match the expected result, this is a finding.
V-239143
False
PHTN-67-000072
At the command line, execute the following command:
# auditctl -l | grep -E "faillog|lastlog|tallylog"
Expected result:
-w /var/log/faillog -p wa
-w /var/log/lastlog -p wa
-w /var/log/tallylog -p wa
If the output does not match the expected result, this is a finding.
M
5323