STIGQter STIGQter: STIG Summary: Red Hat Enterprise Linux 9 Security Technical Implementation Guide Version: 2 Release: 9 Benchmark Date: 01 Jul 2026:

RHEL 9 must write audit records to disk.

DISA Rule

SV-258170r991589_rule

Vulnerability Number

V-258170

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

RHEL-09-653105

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the audit system to write log files to the disk.

Edit the /etc/audit/auditd.conf file and add or update the "write_logs" option to "yes":

write_logs = yes

The audit daemon must be restarted for changes to take effect.

Check Contents

Verify that the audit system is configured to write logs to the disk with the following command:

$ sudo grep write_logs /etc/audit/auditd.conf

write_logs = yes

If "write_logs" does not have a value of "yes", the line is commented out, or the line is missing, this is a finding.

Vulnerability Number

V-258170

Documentable

False

Rule Version

RHEL-09-653105

Severity Override Guidance

Verify that the audit system is configured to write logs to the disk with the following command:

$ sudo grep write_logs /etc/audit/auditd.conf

write_logs = yes

If "write_logs" does not have a value of "yes", the line is commented out, or the line is missing, this is a finding.

Check Content Reference

M

Target Key

5551