CIS Ubuntu 14.04 LTS - 4.1.5 Ensure events that modify user/group information are collected
Collect audit events for modifications to user and group identity files
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Collect audit events for modifications to user and group identity files
Collect audit events for changes to network environment files and system calls
Collect audit events for modifications to SELinux/AppArmor mandatory access controls
Collect audit events for login and logout activity from faillog, lastlog, and tallylog
Collect audit events for session initiation from utmp, wtmp, and btmp files
Enable the rsyslog service to ensure system logging is active
Configure rsyslog to capture appropriate logging for all facilities
Configure rsyslog to create log files with restrictive permissions (0640)
Configure rsyslog to forward logs to a remote log host for centralized logging
Configure rsyslog to accept remote messages only on designated log hosts