CIS Ubuntu 14.04 LTS - 4.1.1.3 Ensure audit logs are not automatically deleted
Configure auditd to retain all audit logs by setting max_log_file_action to keep_logs
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Configure auditd to retain all audit logs by setting max_log_file_action to keep_logs
Collect audit events for file permission, ownership, and attribute changes
Collect audit events for execution of setuid and setgid privileged programs
Collect audit events for mount system calls to detect media export activity
Collect audit events for sudo command execution via the sudo log file
Collect audit events for kernel module loading and unloading operations
Set audit configuration to immutable mode requiring reboot for changes
Enable the auditd daemon to record system events for security monitoring
Configure grub to enable auditing for processes that start before auditd
Collect audit events for system date and time modifications to detect tampering