SV-258144r1045286_rule
V-258144
SRG-OS-000032-GPOS-00013
RHEL-09-652030
CAT II
10
Add or update the following lines to the "/etc/rsyslog.conf" file or a file in "/etc/rsyslog.d":
auth.*;authpriv.*;daemon.* /var/log/secure
The "rsyslog" service must be restarted for the changes to take effect with the following command:
$ sudo systemctl restart rsyslog.service
Verify that RHEL 9 monitors all remote access methods.
Check that remote access methods are being logged by running the following command:
$ grep -rE '(auth.\*|authpriv.\*|daemon.\*)' /etc/rsyslog.conf /etc/rsyslog.d/
/etc/rsyslog.conf:authpriv.*
If "auth.*", "authpriv.*" or "daemon.*" are not configured to be logged, this is a finding.
V-258144
False
RHEL-09-652030
Verify that RHEL 9 monitors all remote access methods.
Check that remote access methods are being logged by running the following command:
$ grep -rE '(auth.\*|authpriv.\*|daemon.\*)' /etc/rsyslog.conf /etc/rsyslog.d/
/etc/rsyslog.conf:authpriv.*
If "auth.*", "authpriv.*" or "daemon.*" are not configured to be logged, this is a finding.
M
5551