Skip to content

Nutanix AOS must produce audit records containing information to establish the source of events.

An XCCDF Rule

Description

<VulnDiscussion>Without establishing the source of the event, it is impossible to establish, correlate, and investigate the events leading up to an outage or attack. In addition to logging where events occur within the operating system, the operating system must also generate audit records that identify sources of events. Sources of operating system events include, but are not limited to, processes, and services. To compile an accurate risk assessment and provide forensic analysis, it is essential for security personnel to know the source of the event.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

ID
SV-254167r846589_rule
Severity
Medium
References
Updated



Remediation - Manual Procedure

Enable the auditd service to run automatically.

$ sudo systemctl enable auditd