CCI-001858
Provide an alert in an organization-defined real-time-period to organization-defined personnel, roles, and/or locations when organization-defined audit failure events requiring real-time alerts occur.
1 rule found Severity: Low

Log aggregation/SIEM systems must be configured to notify SA and ISSO on Docker Engine - Enterprise audit failure events.
1 rule found Severity: Medium

The FortiGate device must generate an immediate real-time alert of all audit failure events requiring real-time alerts.
1 rule found Severity: Medium

If communication with the central audit server is lost, the FortiGate firewall must generate a real-time alert to, at a minimum, the SCA and ISSO.
1 rule found Severity: Medium

The HP FlexFabric Switch must generate an immediate real-time alert of all audit failure events requiring real-time alerts.
1 rule found Severity: Medium

SNMP must be changed from default settings and must be configured on the storage system to provide alerts of critical events that impact system security.
1 rule found Severity: Medium

The HYCU Web UI must generate an immediate real-time alert of all audit failure events requiring real-time alerts.
1 rule found Severity: Medium

1 rule found Severity: Low

The DataPower Gateway must provide an immediate real-time alert to, at a minimum, the SCA and ISSO, of all audit failure events where the detection and/or prevention function is unable to write events to either local storage or the centralized server.
1 rule found Severity: Medium

The MQ Appliance messaging server must alert the SA and ISSO, at a minimum, in the event of a log processing failure.
1 rule found Severity: Medium

DB2 must provide an immediate real-time alert to appropriate support staff of all audit failure events requiring real-time alerts.
1 rule found Severity: Medium

The WebSphere Application Server must provide an immediate real-time alert to authorized users of all log failure events requiring real-time alerts.
1 rule found Severity: Medium

The MQ Appliance network device must generate an immediate alert when allocated audit record storage volume reaches 75 percent of repository maximum audit record storage capacity.
1 rule found Severity: Medium

MobileIron Sentry must generate an immediate real-time alert of all audit failure events requiring real-time alerts.
1 rule found Severity: Low

SQL Server or software monitoring SQL Server must provide an immediate real-time alert to appropriate support staff of all audit log failures.
1 rule found Severity: Medium

Nutanix AOS must provide an immediate warning to the SA and ISSO, at a minimum, when allocated log record storage volume reaches 75 percent of maximum log record storage capacity.
1 rule found Severity: Medium

Riverbed Optimization System (RiOS) must generate an email alert of all log failure events requiring alerts.
1 rule found Severity: Medium

Symantec ProxySG must provide an alert to, at a minimum, the SCA and ISSO of all audit failure events where the detection and/or prevention function is unable to write events to either local storage or the centralized server.
1 rule found Severity: Medium

A Tanium connector must be configured to send log data to an external audit log reduction-capable system and provide alerts.
1 rule found Severity: Medium

Symantec ProxySG must generate an alert to the console when a log processing failure is detected such as loss of communications with the Central Log Server or log records are no longer being sent.
1 rule found Severity: Low

The Tanium enterprise audit log reduction option must be configured to provide alerts based off Tanium audit data.
1 rule found Severity: Medium

The Tanium application must provide an immediate real-time alert to the SA and ISSO, at a minimum, of all audit failure events requiring real-time alerts.
2 rules found Severity: Medium

The Tanium operating system (TanOS) must provide an immediate real-time alert to the SA and ISSO, at a minimum, of all audit failure events requiring real-time alerts.
2 rules found Severity: Medium

The macOS system must provide an immediate real-time alert to the System Administrator (SA) and Information System Security Officer (ISSO), at a minimum, of all audit failure events requiring real-time alerts.
2 rules found Severity: Medium

MongoDB must provide audit record generation for DoD-defined auditable events within all DBMS/database components.
2 rules found Severity: Medium

1 rule found Severity: Medium

PostgreSQL must provide an immediate real-time alert to appropriate support staff of all audit log failures.
2 rules found Severity: Medium

The EDB Postgres Advanced Server must provide an immediate real-time alert to appropriate support staff of all audit failure events requiring real-time alerts.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

The Cisco ASA must be configured to generate a real-time alert to organization-defined personnel and/or the firewall administrator in the event communication with the central audit server is lost.
1 rule found Severity: Medium

The Cisco ASA must be configured to generate an immediate real-time alert of all audit failure events requiring real-time alerts.
1 rule found Severity: Medium

The Cisco ASA must be configured to generate an alert that can be forwarded as an alert to organization-defined personnel and/or firewall administrator of all log failure events.
1 rule found Severity: Medium

3 rules found Severity: Medium

3 rules found Severity: Medium

The Cisco ISE must send an alarm to one or more individuals when the monitoring collector process has an error or failure.
1 rule found Severity: Medium

The Cisco ISE must generate a critical alert to be sent to the ISSO and SA (at a minimum) in the event of an audit processing failure. This is required for compliance with C2C Step 1.
1 rule found Severity: Medium

The Cisco ISE must provide an alert to, at a minimum, the SA and ISSO of all audit failure events where the detection and/or prevention function is unable to write events to either local storage or the centralized server. This is required for compliance with C2C Step 1.
1 rule found Severity: Medium

The EDB Postgres Advanced Server must provide an immediate real-time alert to appropriate support staff of all audit log failures.
1 rule found Severity: Medium

The F5 BIG-IP appliance must generate audit records and send records to redundant central syslog servers that are separate from the appliance.
1 rule found Severity: High

The HPE 3PAR OS must provide an immediate real-time alert to the System Administrator (SA) and Information System Security Officer (ISSO), at a minimum, of all audit failure events requiring real-time alerts.
1 rule found Severity: Medium

1 rule found Severity: High

The ICS must be configured to forward all log failure events where the detection and/or prevention function is unable to write events to local log record or send an SNMP trap that can be forwarded to the SCA and ISSO.
1 rule found Severity: Medium

Sentry must generate an immediate real-time alert of all audit failure events requiring real-time alerts.
1 rule found Severity: Low

The Juniper EX switch must be configured to generate an immediate real-time alert of all audit failure events requiring real-time alerts.
1 rule found Severity: Medium

MarkLogic Server must provide an immediate real-time alert to appropriate support staff of all audit failures.
1 rule found Severity: Medium

MongoDB must provide an immediate real-time alert to appropriate support staff of all audit log failures.
1 rule found Severity: Medium

The network device must generate an immediate real-time alert of all audit failure events requiring real-time alerts.
1 rule found Severity: Medium

The MySQL Database Server 8.0 must provide an immediate real-time alert to appropriate support staff of all audit log failures.
1 rule found Severity: Medium

Redis Enterprise DBMS must provide an immediate real-time alert to appropriate support staff of all audit log failures.
1 rule found Severity: Medium

Rancher MCM must allocate audit record storage and generate audit records associated with events, users, and groups.
1 rule found Severity: Medium

Splunk Enterprise must notify the System Administrator (SA) and Information System Security Officer (ISSO) (at a minimum) of all audit failure events, such as loss of communications with hosts and devices, or if log records are no longer being received.
2 rules found Severity: Low

The Tanium application must provide an immediate real-time alert to the system administrator and information system security officer, at a minimum, of all audit failure events requiring real-time alerts.
1 rule found Severity: Medium

1 rule found Severity: Medium

The application server must provide an immediate real-time alert to authorized users of all log failure events requiring real-time alerts.
1 rule found Severity: Medium

The ALG must provide an immediate real-time alert to, at a minimum, the SCA and ISSO, of all audit failure events where the detection and/or prevention function is unable to write events to either local storage or the centralized server.
1 rule found Severity: Medium

Applications categorized as having a moderate or high impact must provide an immediate real-time alert to the SA and ISSO (at a minimum) for all audit failure events.
1 rule found Severity: Medium

For the host and devices within its scope of coverage, the Central Log Server must be configured to send a real-time alert to the System Administrator (SA) and Information System Security Officer (ISSO) (at a minimum) of all audit failure events, such as loss of communications with hosts and devices, or if log records are no longer being received.
1 rule found Severity: Low

The container platform must provide an immediate real-time alert to the SA and ISSO, at a minimum, of all audit failure events requiring real-time alerts.
1 rule found Severity: Medium

The DBMS must provide an immediate real-time alert to appropriate support staff of all audit log failures.
1 rule found Severity: Medium

If communication with the central audit server is lost, the firewall must generate a real-time alert to, at a minimum, the SCA and ISSO.
1 rule found Severity: Medium

The Dell OS10 Switch must generate an immediate real-time alert of all audit failure events requiring real-time alerts.
1 rule found Severity: Medium

Forescout must generate a critical alert to be sent to the Information System Security Officer (ISSO) and Systems Administrator (SA) (at a minimum) in the event of an audit processing failure. This is required for compliance with C2C Step 1.
1 rule found Severity: Medium

AOS must generate an immediate real-time alert of all audit failure events requiring real-time alerts.
1 rule found Severity: Medium

The HYCU virtual appliance must generate an immediate real-time alert of all audit failure events requiring real-time alerts.
1 rule found Severity: Medium

The operating system must provide an immediate real-time alert to the SA and ISSO, at a minimum, of all audit failure events requiring real-time alerts.
1 rule found Severity: Medium

The IDPS must provide an alert to, at a minimum, the system administrator and ISSO when any audit failure events occur.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

The Juniper SRX Services Gateway must generate an immediate system alert message to the management console when a log processing failure is detected.
1 rule found Severity: Medium

The Mainframe Product must provide an immediate real-time alert to the operations staff, system programmers, and/or security administrators, at a minimum, of all audit failure events requiring real-time alerts.
1 rule found Severity: Medium

MariaDB must provide an immediate real-time alert to appropriate support staff of all audit failure events requiring real-time alerts.
1 rule found Severity: Medium

SQL Server must provide an immediate real-time alert to appropriate support staff of all audit log failures.
1 rule found Severity: Medium

1 rule found Severity: Medium

OpenShift must configure Alert Manger Receivers to notify SA and ISSO of all audit failure events requiring real-time alerts.
1 rule found Severity: Medium

2 rules found Severity: High

The VMM must provide an immediate real-time alert to the SA and ISSO, at a minimum, of all audit failure events requiring real-time alerts.
1 rule found Severity: Medium

1 rule found Severity: Medium

The vCenter server must provide an immediate real-time alert to the system administrator (SA) and information system security officer (ISSO), at a minimum, of all audit failure events requiring real-time alerts.
2 rules found Severity: Medium

vCenter must provide an immediate real-time alert to the system administrator (SA) and information system security officer (ISSO), at a minimum, of all audit failure events requiring real-time alerts.
1 rule found Severity: Medium

2 rules found Severity: Medium

The VPN Gateway must generate a log record or an SNMP trap that can be forwarded as an alert to, at a minimum, the SCA and ISSO, of all log failure events where the detection and/or prevention function is unable to write events to either local storage or the centralized server.
1 rule found Severity: Medium
