STIGUI
V-282425CAT II — Medium severitySV-282425r1201625_rule

TOSS 5 must label all offloaded audit logs before sending them to the central log server.

Rule version TOSS-05-000396 · STIG v1 · 2026-08-20

Discussion

Enriched logging is needed to determine who, what, and when events occur on a system. Without this, determining root cause of an event will be much more difficult.

When audit logs are not labeled before they are sent to a central log server, the audit data will not be able to be analyzed and tied back to the correct system.

Check

Verify that TOSS 5 Audit Daemon is configured to label all offloaded audit logs, with the following command:

$ sudo grep name_format /etc/audit/auditd.conf

name_format = hostname

If the "name_format" option is not "hostname", "fqd", or "numeric", or the line is commented out, this is a finding.

Fix

Edit the /etc/audit/auditd.conf file and add or update the "name_format" option:

name_format = hostname

Restart the audit daemon for changes to take effect.

Identifiers

Group ID
V-282425
Group title
SRG-OS-000039-GPOS-00017
Rule ID
SV-282425r1201625_rule
Check ID
C-86986r1200253_chk
Fix ID
F-86891r1201624_fix