SV-269538r1050421_rule
V-269538
SRG-OS-000057-GPOS-00027
ALMA-09-055900
CAT II
10
Change the audit logs to be owned by the root group:
$ chgrp root /var/log/audit/audit.log
Then set the group to root in /etc/audit/auditd.conf by adding or updating the following line:
log_group = root
Verify the audit logs are owned by the "root" group.
First determine if a group other than "root" has been assigned to the audit logs with the following command:
$ grep log_group /etc/audit/auditd.conf
log_group = root
Then determine where the audit logs are stored with the following command:
$ grep -w log_file /etc/audit/auditd.conf
log_file = /var/log/audit/audit.log
Then using the location of the audit log file, determine if the audit log is owned by the "root" group using the following command:
$ stat -c "%G" /var/log/audit/audit.log
root
If the audit log is not owned by the "root" group, or log_group is not set to "root", this is a finding.
V-269538
False
ALMA-09-055900
Verify the audit logs are owned by the "root" group.
First determine if a group other than "root" has been assigned to the audit logs with the following command:
$ grep log_group /etc/audit/auditd.conf
log_group = root
Then determine where the audit logs are stored with the following command:
$ grep -w log_file /etc/audit/auditd.conf
log_file = /var/log/audit/audit.log
Then using the location of the audit log file, determine if the audit log is owned by the "root" group using the following command:
$ stat -c "%G" /var/log/audit/audit.log
root
If the audit log is not owned by the "root" group, or log_group is not set to "root", this is a finding.
M
5664