STIGQter STIGQter: STIG Summary: SUSE Linux Enterprise Micro (SLEM) 5 Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 01 Apr 2026:

SLEM 5 audit records must contain information to establish what type of events occurred, the source of events, where events occurred, and the outcome of events.

DISA Rule

SV-261411r996646_rule

Vulnerability Number

V-261411

Group Title

SRG-OS-000037-GPOS-00015

Rule Version

SLEM-05-653015

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Enable SLEM 5 auditd service by using the following commands:

> sudo systemctl enable auditd.service
> sudo systemctl start auditd.service

Check Contents

Verify SLEM 5 produces audit records with the following commands:

> systemctl is-active auditd.service
active

> systemctl is-enabled auditd.service
enabled

If the service is not active or not enabled, this is a finding.

Vulnerability Number

V-261411

Documentable

False

Rule Version

SLEM-05-653015

Severity Override Guidance

Verify SLEM 5 produces audit records with the following commands:

> systemctl is-active auditd.service
active

> systemctl is-enabled auditd.service
enabled

If the service is not active or not enabled, this is a finding.

Check Content Reference

M

Target Key

5596