STIGQter STIGQter: STIG Summary: Red Hat Enterprise Linux 10 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

RHEL 10 must be configured to forward audit records via Transmission Control Protocol (TCP) to a different system or media from the system being audited via rsyslog.

DISA Rule

SV-280985r1197221_rule

Vulnerability Number

V-280985

Group Title

SRG-OS-000479-GPOS-00224

Rule Version

RHEL-10-200642

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure RHEL 10 to off-load audit records onto a different system or media from the system being audited via TCP using rsyslog by specifying the remote logging server in "/etc/rsyslog.conf" or "/etc/rsyslog.d/[customfile].conf" with the name or IP address of the log aggregation server.

Using legacy "@host:port" syntax example:
*.* @@[remoteloggingserver]:[port]

Using Rainer script example:
action(
type="omfwd"
target="logserver.example.com"
port="514"
protocol="tcp"
action.resumeRetryCount="-1"
queue.type="linkedList"
que.size="10000"
)

Note: The Rainer script above does not contain the required encryption settings.

Check Contents

Verify RHEL 10 audit system off-loads audit records onto a different system or media from the system being audited via rsyslog using TCP with the following commands:

To check for legacy configuration syntax, perform the following:

$ sudo grep -ir '@@' /etc/rsyslog.conf /etc/rsyslog.d/

To check for Rainer script syntax, perform the following:

$ sudo grep -rq 'type="omfwd"' /etc/rsyslog.conf /etc/rsyslog.d/

If a remote server is not configured, or the line is commented out, ask the system administrator to indicate how the audit logs are off-loaded to a different system or media.

If there is no evidence that the audit logs are being off-loaded to another system or media, this is a finding.

Vulnerability Number

V-280985

Documentable

False

Rule Version

RHEL-10-200642

Severity Override Guidance

Verify RHEL 10 audit system off-loads audit records onto a different system or media from the system being audited via rsyslog using TCP with the following commands:

To check for legacy configuration syntax, perform the following:

$ sudo grep -ir '@@' /etc/rsyslog.conf /etc/rsyslog.d/

To check for Rainer script syntax, perform the following:

$ sudo grep -rq 'type="omfwd"' /etc/rsyslog.conf /etc/rsyslog.d/

If a remote server is not configured, or the line is commented out, ask the system administrator to indicate how the audit logs are off-loaded to a different system or media.

If there is no evidence that the audit logs are being off-loaded to another system or media, this is a finding.

Check Content Reference

M

Target Key

5733