1. Home
  2. Security Hardening
  3. DISA STIG VMware vSphere 6.7 Photon OS V1R1
  4. PHTN-67-000011 – The Photon operating system must configure auditd to use the correct log format.

PHTN-67-000011 – The Photon operating system must configure auditd to use the correct log format.

Details

To compile an accurate risk assessment and provide forensic analysis, it is essential for security personnel to know exact, unfiltered details of the event in question.

Solution

Open /etc/audit/auditd.conf with a text editor.

Ensure that the ‘log_format’ line is uncommented and set to the following:

log_format = RAW

At the command line, execute the following command:

# service auditd reload

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Audit and Accountability.This control applies to the following type of system Unix.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles