UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

AIX audit logs must be rotated daily.


Overview

Finding ID Version Rule ID IA Controls Severity
V-215256 AIX7-00-002057 SV-215256r508663_rule Medium
Description
Rotate audit logs daily to preserve audit file system space and to conform to the DoD/DISA requirement. If it is not rotated daily and moved to another location, then there is more of a chance for the compromise of audit data by malicious users.
STIG Date
IBM AIX 7.x Security Technical Implementation Guide 2020-09-11

Details

Check Text ( C-16454r294219_chk )
Check for any "crontab" entries that rotate audit logs:

# crontab -l
30 23 * * * /root/logrotate.sh #Daily log rotation script
If such a cron job is found, this is not a finding.

Otherwise, query the SA.

If there is a process automatically rotating audit logs, this is not a finding.

If the SA manually rotates audit logs, this is a finding.

If the audit output is not archived daily, to tape or disk, this is a finding.

Review the audit log directory.

If more than one file is there, or if the file does not have today's date, this is a finding.
Fix Text (F-16452r294220_fix)
Configure a cron job or other automated process to rotate the audit logs on a daily basis.