RHEL 9 must write audit records to disk.

STIG ID: RHEL-09-653105  |  SRG: SRG-OS-000480-GPOS-00227 |  Severity: medium |  CCI: CCI-000366 |  Vulnerability Id: V-258170 | 

Vulnerability Discussion

Audit data should be synchronously written to disk to ensure log integrity. This setting assures that all audit event data is written disk.

Check

Verify that the audit system is configured to write logs to the disk with the following command:

$ sudo grep write_logs /etc/audit/auditd.conf

write_logs = yes

If "write_logs" does not have a value of "yes", the line is commented out, or the line is missing, this is a finding.

Fix

Configure the audit system to write log files to the disk.

Edit the /etc/audit/auditd.conf file and add or update the "write_logs" option to "yes":

write_logs = yes

The audit daemon must be restarted for changes to take effect.