UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The audit event multiplexor must be configured to off-load audit logs onto a different system or storage media from the system being audited.


Overview

Finding ID Version Rule ID IA Controls Severity
V-75659 UBTU-16-020210 SV-90339r2_rule Medium
Description
Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Off-loading is a common process in information systems with limited audit storage capacity.
STIG Date
Canonical Ubuntu 16.04 LTS Security Technical Implementation Guide 2018-07-18

Details

Check Text ( C-75363r2_chk )
Verify the audit event multiplexor is configured to off-load audit records to a different system or storage media from the system being audited.

Check that the records are being off-loaded to a remote server with the following command:

# sudo grep -i active /etc/audisp/plugins.d/au-remote.conf

active = yes

If "active" is not set to "yes", or the line is commented out, this is a finding.
Fix Text (F-82287r2_fix)
Configure the audit event multiplexor to off-load audit records to a different system or storage media from the system being audited.

Set the "active" option in "/etc/audisp/plugins.d/au-remote.conf" to "yes":

active = yes

In order for the changes to take effect, the audit daemon must be restarted. The audit daemon can be restarted with the following command:

# sudo systemctl restart auditd.service