STIGQter STIGQter: STIG Summary: Riverbed NetIM OS Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 11 Sep 2025:

Ubuntu OS must configure the directories used by the system journal to be group-owned by "systemd-journal".

DISA Rule

SV-275596r1147838_rule

Vulnerability Number

V-275596

Group Title

SRG-OS-000206-GPOS-00084

Rule Version

RIIM-OS-232085

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure Ubuntu OS to set the appropriate group-ownership to the directories used by the systemd journal:

Add or modify the following lines in the "/usr/lib/tmpfiles.d/systemd.conf" file:

z /run/log/journal 2640 root systemd-journal - -
z /var/log/journal 2640 root systemd-journal - -

Restart the system for the changes to take effect.

Check Contents

Verify the /run/log/journal and /var/log/journal directories are group-owned by "systemd-journal" by using the following command:

$ sudo find /run/log/journal /var/log/journal -type d -exec stat -c "%n %G" {} \;
/run/log/journal systemd-journal
/var/log/journal systemd-journal
/var/log/journal/3b018e681c904487b11671b9c1987cce systemd-journal

If any output returned is not group-owned by "systemd-journal", this is a finding.

Vulnerability Number

V-275596

Documentable

False

Rule Version

RIIM-OS-232085

Severity Override Guidance

Verify the /run/log/journal and /var/log/journal directories are group-owned by "systemd-journal" by using the following command:

$ sudo find /run/log/journal /var/log/journal -type d -exec stat -c "%n %G" {} \;
/run/log/journal systemd-journal
/var/log/journal systemd-journal
/var/log/journal/3b018e681c904487b11671b9c1987cce systemd-journal

If any output returned is not group-owned by "systemd-journal", this is a finding.

Check Content Reference

M

Target Key

5706