CIS Ubuntu Linux 24.04 LTS Benchmark · Section 6

Ubuntu 24.04 Logging and Auditing: 10 Checks

Wartiva runs 10 checks for section 6, Logging and Auditing, of the CIS Ubuntu Linux 24.04 LTS Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →

All 10 checks on this page

6.1 System Logging

Ensure journald service is active

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 6.1.1.1

Finding: systemd-journald service is not active.

Checks whether the systemd-journald service is loaded and running so that system logging events are captured.

This rule fails when systemd-journald.service is masked, disabled, or not RUNNING.

Rationale: If systemd-journald is not running the system will not capture logging events.

Remediation

From the command line:

systemctl unmask systemd-journald.service
systemctl --now enable systemd-journald.service
Framework mappings
  • CIS Controls v8: 8.2 Collect Audit Logs
  • NIST SP 800-53 Rev. 5: AU-2 Event Logging; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation
  • PCI DSS v4.0.1: 5.3.4 Enable and retain anti-malware audit logs; 6.4.1 Assess or shield public-facing web applications against known attacks; 6.4.2 Deploy an automated solution that blocks attacks on public web apps; 10.2.1.1 Record every individual user's cardholder data access; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.3 Record any access made to audit records themselves; 10.2.1.4 Record failed logical access attempts; 10.2.1.5 Record account creation, privilege elevation, and other credential changes; 10.2.1.6 Record when audit logging is initialized, started, stopped, or paused; 10.2.1.7 Record the creation or removal of system-level objects; 10.2.2 Include user, event type, date, and time in each log entry
Risk
Reliability Impact
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure systemd-journal-remote service is not in use

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 6.1.1.1

Finding: systemd-journal-remote service is in use.

Checks that the systemd-journal-remote socket and service are masked or stopped so the host does not act as a remote journal log receiver.

This rule fails when the service unit is loaded (not masked) and RUNNING.

Rationale: A client configured to also receive remote logs becomes a log server and operates outside its intended boundary.

Impact: The host will no longer be able to receive journal logs from remote hosts.

Remediation

From the command line:

systemctl stop systemd-journal-remote.socket systemd-journal-remote.service
systemctl mask systemd-journal-remote.socket systemd-journal-remote.service
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure rsyslog service is enabled and active

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 6.1.2

Finding: Rsyslog service is not enabled and active.

Checks whether the rsyslog service is enabled to start on boot and currently running so logging events are captured.

This rule fails when rsyslog.service is masked, disabled, or not RUNNING.

Rationale: If rsyslog is not enabled to start on boot the system will not capture logging events.

Remediation

From the command line:

systemctl unmask rsyslog.service
systemctl enable rsyslog.service
systemctl start rsyslog.service
Framework mappings
  • CIS Controls v8: 8.2 Collect Audit Logs
  • NIST SP 800-53 Rev. 5: AU-2 Event Logging; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation
  • PCI DSS v4.0.1: 5.3.4 Enable and retain anti-malware audit logs; 6.4.1 Assess or shield public-facing web applications against known attacks; 6.4.2 Deploy an automated solution that blocks attacks on public web apps; 10.2.1.1 Record every individual user's cardholder data access; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.3 Record any access made to audit records themselves; 10.2.1.4 Record failed logical access attempts; 10.2.1.5 Record account creation, privilege elevation, and other credential changes; 10.2.1.6 Record when audit logging is initialized, started, stopped, or paused; 10.2.1.7 Record the creation or removal of system-level objects; 10.2.2 Include user, event type, date, and time in each log entry
Risk
Reliability Impact
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure rsyslog is installed

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 6.1.2

Finding: Rsyslog package is not installed.

Checks that the rsyslog package is installed.

This rule fails when the package is not installed.

Rationale: rsyslog provides connection-oriented transmission and encryption of log data, strengthening log collection and export.

Scope: Ubuntu 24.04 and later endpoints.

Remediation

From the command line:

apt install rsyslog
Framework mappings
  • CIS Controls v8: 8.2 Collect Audit Logs
  • NIST SP 800-53 Rev. 5: AU-2 Event Logging; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation
  • PCI DSS v4.0.1: 5.3.4 Enable and retain anti-malware audit logs; 6.4.1 Assess or shield public-facing web applications against known attacks; 6.4.2 Deploy an automated solution that blocks attacks on public web apps; 10.2.1.1 Record every individual user's cardholder data access; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.3 Record any access made to audit records themselves; 10.2.1.4 Record failed logical access attempts; 10.2.1.5 Record account creation, privilege elevation, and other credential changes; 10.2.1.6 Record when audit logging is initialized, started, stopped, or paused; 10.2.1.7 Record the creation or removal of system-level objects; 10.2.2 Include user, event type, date, and time in each log entry
Risk
Reliability Impact
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure rsyslog-gnutls is installed

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 6.1.2

Finding: rsyslog-gnutls package is not installed.

Checks that the rsyslog-gnutls package is installed.

This rule fails when the package is not installed.

Rationale: Traditional syslog is clear text; rsyslog-gnutls enables TLS encryption of syslog communication in transit.

Scope: Ubuntu 24.04 and later endpoints.

Remediation

From the command line:

apt install rsyslog-gnutls
Framework mappings
  • CIS Controls v8: 8.2 Collect Audit Logs
  • NIST SP 800-53 Rev. 5: AU-2 Event Logging; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation
  • PCI DSS v4.0.1: 5.3.4 Enable and retain anti-malware audit logs; 6.4.1 Assess or shield public-facing web applications against known attacks; 6.4.2 Deploy an automated solution that blocks attacks on public web apps; 10.2.1.1 Record every individual user's cardholder data access; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.3 Record any access made to audit records themselves; 10.2.1.4 Record failed logical access attempts; 10.2.1.5 Record account creation, privilege elevation, and other credential changes; 10.2.1.6 Record when audit logging is initialized, started, stopped, or paused; 10.2.1.7 Record the creation or removal of system-level objects; 10.2.2 Include user, event type, date, and time in each log entry
Risk
Reliability Impact
MITRE ATT&CK tactic
Defense Evasion (TA0005)

6.2 System Auditing

Ensure auditd service is enabled and active

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 6.2.1

Finding: Auditd service is not enabled and active.

Checks whether the auditd daemon is enabled to start on boot and currently running so system events are recorded.

This rule fails when auditd.service is masked, disabled, or not RUNNING.

Rationale: Capturing system events lets administrators determine whether unauthorized access is occurring.

Remediation

From the command line:

systemctl unmask auditd
systemctl enable auditd
systemctl start auditd
Framework mappings
  • CIS Controls v8: 8.2 Collect Audit Logs
  • NIST SP 800-53 Rev. 5: AU-2 Event Logging; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation
  • PCI DSS v4.0.1: 5.3.4 Enable and retain anti-malware audit logs; 6.4.1 Assess or shield public-facing web applications against known attacks; 6.4.2 Deploy an automated solution that blocks attacks on public web apps; 10.2.1.1 Record every individual user's cardholder data access; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.3 Record any access made to audit records themselves; 10.2.1.4 Record failed logical access attempts; 10.2.1.5 Record account creation, privilege elevation, and other credential changes; 10.2.1.6 Record when audit logging is initialized, started, stopped, or paused; 10.2.1.7 Record the creation or removal of system-level objects; 10.2.2 Include user, event type, date, and time in each log entry
Risk
Reliability Impact
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure auditd is installed

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 6.2.1

Finding: Auditd package is not installed.

Checks that the auditd package is installed.

This rule fails when the package is not installed.

Rationale: Capturing system events lets administrators determine whether unauthorized access is occurring.

Scope: Ubuntu 24.04 and later endpoints.

Remediation

From the command line:

apt install auditd
Framework mappings
  • CIS Controls v8: 8.5 Collect Detailed Audit Logs
  • NIST SP 800-53 Rev. 5: AU-3 Content of Audit Records; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation; SI-4 System Monitoring
  • PCI DSS v4.0.1: 9.4.5 Keep a log-based inventory of electronic media holding cardholder data; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.5 Record account creation, privilege elevation, and other credential changes
Risk
Reliability Impact
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure audispd-plugins is installed

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 6.2.1

Finding: audispd-plugins package is not installed.

Checks that the audispd-plugins package is installed.

This rule fails when the package is not installed.

Rationale: Capturing system events lets administrators determine whether unauthorized access is occurring.

Scope: Ubuntu 24.04 and later endpoints.

Remediation

From the command line:

apt install audispd-plugins
Framework mappings
  • CIS Controls v8: 8.5 Collect Detailed Audit Logs
  • NIST SP 800-53 Rev. 5: AU-3 Content of Audit Records; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation; SI-4 System Monitoring
  • PCI DSS v4.0.1: 9.4.5 Keep a log-based inventory of electronic media holding cardholder data; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.5 Record account creation, privilege elevation, and other credential changes
Risk
Reliability Impact
MITRE ATT&CK tactic
Defense Evasion (TA0005)

6.3 Configure Integrity Checking

Ensure aide is installed

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 6.3

Finding: Aide package is not installed.

Checks that the aide package is installed.

This rule fails when the package is not installed.

Rationale: A host-based integrity tool detects tampering with critical system files and binaries.

Scope: Ubuntu 24.04 and later endpoints.

Remediation

From the command line:

apt install aide
Framework mappings
  • CIS Controls v8: 3.14 Log Sensitive Data Access
  • NIST SP 800-53 Rev. 5: AC-6 Least Privilege; AU-2 Event Logging; AU-12 Audit Record Generation; SI-4 System Monitoring
  • PCI DSS v4.0.1: 10.2.1.1 Record every individual user's cardholder data access
Risk
Reliability Impact
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure aide-common is installed

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 6.3

Finding: aide-common package is not installed.

Checks that the aide-common package is installed.

This rule fails when the package is not installed.

Rationale: A host-based integrity tool detects tampering with critical system files and binaries.

Scope: Ubuntu 24.04 and later endpoints.

Remediation

From the command line:

apt install aide-common
Framework mappings
  • CIS Controls v8: 3.14 Log Sensitive Data Access
  • NIST SP 800-53 Rev. 5: AC-6 Least Privilege; AU-2 Event Logging; AU-12 Audit Record Generation; SI-4 System Monitoring
  • PCI DSS v4.0.1: 10.2.1.1 Record every individual user's cardholder data access
Risk
Reliability Impact
MITRE ATT&CK tactic
Defense Evasion (TA0005)