STIGQter STIGQter: STIG Summary: Canonical Ubuntu 24.04 LTS Security Technical Implementation Guide Version: 1 Release: 6 Benchmark Date: 01 Jul 2026:

Ubuntu 24.04 LTS must configure the files used by the system journal to be group-owned by "systemd-journal".

DISA Rule

SV-270762r1184076_rule

Vulnerability Number

V-270762

Group Title

SRG-OS-000206-GPOS-00084

Rule Version

UBTU-24-700070

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the system to set the appropriate group-ownership to the files used by the systemd journal.

Create a drop-in file if it does not already exist with the following command:

$ sudo vi /etc/tmpfiles.d/zzz-systemd-stig.conf

Add or modify the following lines in the "/usr/lib/tmpfiles.d/zzz-systemd-stig.conf" file:

Z /run/log/journal/%m ~0640 root systemd-journal - -
z /var/log/journal/%m 0640 root systemd-journal - -
z /var/log/journal/%m/system.journal 0640 root systemd-journal - -

Note: Restart the system for these settings to take effect.

Check Contents

Verify the /run/log/journal and /var/log/journal files are group-owned by "systemd-journal" with the following command:

$ sudo find /run/log/journal /var/log/journal -type f -exec stat -c "%n %G" {} \;
/var/log/journal/d5745ad455d34fb8b6f78be37c1fcd3e/system.journal systemd-journal
/var/log/journal/d5745ad455d34fb8b6f78be37c1fcd3e/user-1000@0005f97cd4a8c9b5-f088232c3718485a.journal~ systemd-journal
/var/log/journal/d5745ad455d34fb8b6f78be37c1fcd3e/system@0005f97cd2a1e0a7-d58b848af46813a4.journal~ systemd-journal
/var/log/journal/d5745ad455d34fb8b6f78be37c1fcd3e/system@0005f97cb900e501-55ea053b7f75ae1c.journal~ systemd-journal
/var/log/journal/d5745ad455d34fb8b6f78be37c1fcd3e/user-1000.journal systemd-journal

If any output returned is not group-owned by "systemd-journal", this is a finding.

Vulnerability Number

V-270762

Documentable

False

Rule Version

UBTU-24-700070

Severity Override Guidance

Verify the /run/log/journal and /var/log/journal files are group-owned by "systemd-journal" with the following command:

$ sudo find /run/log/journal /var/log/journal -type f -exec stat -c "%n %G" {} \;
/var/log/journal/d5745ad455d34fb8b6f78be37c1fcd3e/system.journal systemd-journal
/var/log/journal/d5745ad455d34fb8b6f78be37c1fcd3e/user-1000@0005f97cd4a8c9b5-f088232c3718485a.journal~ systemd-journal
/var/log/journal/d5745ad455d34fb8b6f78be37c1fcd3e/system@0005f97cd2a1e0a7-d58b848af46813a4.journal~ systemd-journal
/var/log/journal/d5745ad455d34fb8b6f78be37c1fcd3e/system@0005f97cb900e501-55ea053b7f75ae1c.journal~ systemd-journal
/var/log/journal/d5745ad455d34fb8b6f78be37c1fcd3e/user-1000.journal systemd-journal

If any output returned is not group-owned by "systemd-journal", this is a finding.

Check Content Reference

M

Target Key

5673