RHEL 9 audispd-plugins package must be installed.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-258175RHEL-09-653130SV-258175r1045310_ruleCCI-001851medium
Description
"audispd-plugins" provides plugins for the real-time interface to the audit subsystem, "audispd". These plugins can do things like relay events to remote machines or analyze events for suspicious behavior.
STIGDate
Red Hat Enterprise Linux 9 Security Technical Implementation Guide2025-05-14

Details

Check Text (C-258175r1045310_chk)

Verify that RHEL 9 has the audispd-plugins package installed with the following command: $ dnf list --installed audispd-plugins Example output: audispd-plugins.x86_64 3.0.7-101.el9_0.2 If the "audispd-plugins" package is not installed, this is a finding.

Fix Text (F-61840r926511_fix)

The audispd-plugins package can be installed with the following command: $ sudo dnf install audispd-plugins