STIGQter STIGQter: STIG Summary: Amazon Linux 2023 Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 01 Jul 2026:

Amazon Linux 2023 must produce audit records containing information to establish the identity of any individual or process associated with the event.

DISA Rule

SV-274115r1120333_rule

Vulnerability Number

V-274115

Group Title

SRG-OS-000255-GPOS-00096

Rule Version

AZLX-23-002260

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure Amazon Linux 2023 so that the audit system resolves audit information before writing to disk.

Edit the /etc/audit/auditd.conf file and add or update the "log_format" option:

log_format = ENRICHED

The audit daemon must be restarted for changes to take effect.

Check Contents

Verify Amazon Linux 2023 is configured so that the audit system resolves audit information before writing to disk, with the following command:

$ sudo grep log_format /etc/audit/auditd.conf
log_format = ENRICHED

If the "log_format" option is not "ENRICHED", or the line is commented out, this is a finding.

Vulnerability Number

V-274115

Documentable

False

Rule Version

AZLX-23-002260

Severity Override Guidance

Verify Amazon Linux 2023 is configured so that the audit system resolves audit information before writing to disk, with the following command:

$ sudo grep log_format /etc/audit/auditd.conf
log_format = ENRICHED

If the "log_format" option is not "ENRICHED", or the line is commented out, this is a finding.

Check Content Reference

M

Target Key

5700