UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The operating system must provide a real-time alert when organization-defined audit failure events occur.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-OS-000049-ESXI5-PNF SRG-OS-000049-ESXI5-PNF SRG-OS-000049-ESXI5-PNF_rule Medium
Description
It is critical for the appropriate personnel to be aware if a system is at risk of failing to process audit logs as required. Audit processing failures include, software/hardware errors, failures in the audit capturing mechanisms, and audit storage capacity being reached or exceeded. Organizations must define audit failure events requiring an application to send an alarm. When those defined events occur, the application will provide a real-time alert to the appropriate personnel. Permanent not a finding - Remote logging is a VMware HG requirement. Due to remote logging, audit records are stored off-system. With hardware/software failures, the machine's status is tracked by the vCenter Server. The vSphere/vCenter Server host health monitoring tool allows you to monitor the health of a variety of host hardware components including: CPU processors, Memory, Fans, Temperature, Voltage, Power, Network, Battery, Storage, Cable/Interconnect, Software components, and Watchdog. SNMP alerts are supported.
STIG Date
VMware ESXi v5 Security Technical Implementation Guide 2013-01-15

Details

Check Text ( C-SRG-OS-000049-ESXI5-PNF_chk )
ESXi supports this requirement and cannot be configured to be out of compliance. This is a permanent not a finding.
Fix Text (F-SRG-OS-000049-ESXI5-PNF_fix)
This requirement is permanent not a finding. No fix is required.