Amazon Linux 2023 must label all off-loaded audit logs before sending them to the central log server.
Overview
| Finding ID | Version | Rule ID | IA Controls | Severity |
| V-274069 | AZLX-23-002025 | SV-274069r1120195_rule | CCI-001851 | medium |
| Description | ||||
| Enriched logging is needed to determine who, what, and when events occur on a system. Without this, determining root cause of an event will be much more difficult. | ||||
| STIG | Date | |||
| Amazon Linux 2023 Security Technical Implementation Guide | 2026-02-27 | |||
Details
Check Text (C-274069r1120195_chk)
Verify Amazon Linux 2023 is configured so that the Audit Daemon labels all off-loaded audit logs with the following command:
$ sudo grep name_format /etc/audit/auditd.conf
name_format = hostname
If the "name_format" option is not "hostname", "fqd", or "numeric", or the line is commented out, this is a finding.
Fix Text (F-78065r1120194_fix)
Configure Amazon Linux 2023 to be configured so that the Audit Daemon labels all off-loaded audit logs.
Edit the /etc/audit/auditd.conf file and add or update the "name_format" option:
name_format = hostname
The audit daemon must be restarted for changes to take effect.