RHEL 10 must write audit records to disk.

STIG ID: RHEL-10-500015  |  SRG: SRG-OS-000058-GPOS-00028 |  Severity: medium (CAT II)  |  CCI: CCI-000163 |  Vulnerability Id: V-281099

Vulnerability Discussion

Audit data must be synchronously written to disk to ensure log integrity. This setting ensures that all audit event data is written to disk.

Check

Verify the RHEL 10 audit system is configured to write logs to the disk with the following command:

$ sudo grep write_logs /etc/audit/auditd.conf
write_logs = yes

If "write_logs" does not have a value of "yes", the line is commented out, or the line is missing, this is a finding.

Fix

Configure the RHEL 10 audit system to write log files to the disk.

Edit the "/etc/audit/auditd.conf" file and add or update the "write_logs" option to "yes":

write_logs = yes

Restart the audit daemon with the following command for changes to take effect:

$ sudo service auditd restart