STIGQter STIGQter: STIG Summary: Oracle Linux 9 Security Technical Implementation Guide Version: 1 Release: 6 Benchmark Date: 01 Jul 2026:

OL 9 must be configured to forward audit records via TCP to a different system or media from the system being audited via rsyslog.

DISA Rule

SV-271852r1184227_rule

Vulnerability Number

V-271852

Group Title

SRG-OS-000479-GPOS-00224

Rule Version

OL09-00-005005

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure OL 9 to offload audit records onto a different system or media from the system being audited via TCP using rsyslog by specifying the remote logging server in "/etc/rsyslog.conf" or "/etc/rsyslog.d/[customfile].conf" with the name or IP address of the log aggregation server. Following are examples of the configuration for the legacy syntax and for the newer Rainer script. Only one should be used.

Using legacy '@host:port" syntax example:
*.* @@[remoteloggingserver]:[port]

Using Rainer script example:
action(
type="omfwd"
target="logserver.example.com"
port="514"
protocol="tcp"
action.resumeRetryCount="-1"
queue.type="linkedList"
que.size="10000"
)

Note: The Rainer Script above does not contain the required encryption settings.

Check Contents

Verify OL 9 audit system offloads audit records onto a different system or media from the system being audited via rsyslog using TCP with the following commands:

To check for legacy configuration syntax, perform the following:
$ sudo grep -ir '@@' /etc/rsyslog.conf /etc/rsyslog.d/

To check for Rainer script syntax, perform the following:
$ sudo grep -rq 'type="omfwd"' /etc/rsyslog.conf /etc/rsyslog.d/

If a remote server is not configured, or the line is commented out, ask the system administrator (SA) to indicate how the audit logs are offloaded to a different system or media.

If there is no evidence that the audit logs are being offloaded to another system or media, this is a finding.

Vulnerability Number

V-271852

Documentable

False

Rule Version

OL09-00-005005

Severity Override Guidance

Verify OL 9 audit system offloads audit records onto a different system or media from the system being audited via rsyslog using TCP with the following commands:

To check for legacy configuration syntax, perform the following:
$ sudo grep -ir '@@' /etc/rsyslog.conf /etc/rsyslog.d/

To check for Rainer script syntax, perform the following:
$ sudo grep -rq 'type="omfwd"' /etc/rsyslog.conf /etc/rsyslog.d/

If a remote server is not configured, or the line is commented out, ask the system administrator (SA) to indicate how the audit logs are offloaded to a different system or media.

If there is no evidence that the audit logs are being offloaded to another system or media, this is a finding.

Check Content Reference

M

Target Key

5680