SV-248816r958754_rule
V-248816
SRG-OS-000342-GPOS-00133
OL08-00-030710
CAT II
10
Configure the operating system to encrypt offloaded audit records by setting the following options in "/etc/rsyslog.conf" or "/etc/rsyslog.d/[customfile].conf":
$DefaultNetstreamDriver gtls
$ActionSendStreamDriverMode 1
Verify the operating system encrypts audit records offloaded onto a different system or media from the system being audited with the following commands:
$ sudo grep -i '$DefaultNetstreamDriver' /etc/rsyslog.conf /etc/rsyslog.d/*.conf
/etc/rsyslog.conf:$DefaultNetstreamDriver gtls
If the value of the "$DefaultNetstreamDriver" option is not set to "gtls" or the line is commented out, this is a finding.
$ sudo grep -i '$ActionSendStreamDriverMode' /etc/rsyslog.conf /etc/rsyslog.d/*.conf
/etc/rsyslog.conf:$ActionSendStreamDriverMode 1
If the value of the "$ActionSendStreamDriverMode" option is not set to "1" or the line is commented out, this is a finding.
If neither of the definitions above are set, ask the System Administrator to indicate how the audit logs are offloaded to a different system or media.
If there is no evidence that the transfer of the audit logs being offloaded to another system or media is encrypted, this is a finding.
V-248816
False
OL08-00-030710
Verify the operating system encrypts audit records offloaded onto a different system or media from the system being audited with the following commands:
$ sudo grep -i '$DefaultNetstreamDriver' /etc/rsyslog.conf /etc/rsyslog.d/*.conf
/etc/rsyslog.conf:$DefaultNetstreamDriver gtls
If the value of the "$DefaultNetstreamDriver" option is not set to "gtls" or the line is commented out, this is a finding.
$ sudo grep -i '$ActionSendStreamDriverMode' /etc/rsyslog.conf /etc/rsyslog.d/*.conf
/etc/rsyslog.conf:$ActionSendStreamDriverMode 1
If the value of the "$ActionSendStreamDriverMode" option is not set to "1" or the line is commented out, this is a finding.
If neither of the definitions above are set, ask the System Administrator to indicate how the audit logs are offloaded to a different system or media.
If there is no evidence that the transfer of the audit logs being offloaded to another system or media is encrypted, this is a finding.
M
5416