STIGUI
V-282752CAT II — Medium severitySV-282752r1201236_rule

TOSS 5 must write audit records to disk.

Rule version TOSS-05-000405 · STIG v1 · 2026-08-20

Discussion

Audit data should be synchronously written to disk to ensure log integrity. This setting ensures all audit event data is written to disk.

Check

If the system is configured to immediately offload audit records to an external system, this requirement is not applicable.

Verify the audit system is configured to write logs to the disk using the following command:

$ sudo grep write_logs /etc/audit/auditd.conf 

write_logs = yes

If "write_logs" does not have a value of "yes", the line is commented out, or the line is missing, this is a finding.

Fix

Configure the audit system to write log files to the disk.

Edit the "/etc/audit/auditd.conf" file and add or update the "write_logs" option to "yes":

write_logs = yes

Restart the audit daemon for changes to take effect.

Identifiers

Group ID
V-282752
Group title
SRG-OS-000480-GPOS-00227
Rule ID
SV-282752r1201236_rule
Check ID
C-87313r1201234_chk
Fix ID
F-87218r1201235_fix