---
title: CIS Ubuntu 24.04 Logging and Auditing: 10 Checks | Wartiva
description: Wartiva's 10 checks for section 6, Logging and Auditing, of the CIS Ubuntu Linux 24.04 LTS Benchmark: what each one finds, why it matters, and how to fix it.
url: https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/logging-and-auditing.html
updated: 2026-10-07
---

CIS Ubuntu Linux 24.04 LTS Benchmark · Section 6

# Ubuntu 24.04 Logging and Auditing: 10 Checks

Wartiva runs 10 checks for section 6, Logging and Auditing, of the CIS Ubuntu Linux 24.04 LTS Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. [How Wartiva works →](https://wartiva.com/platform.html)

## 6.1 System Logging

### [Ensure journald service is active](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/logging-and-auditing.html#journald-service-is-active)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 6.1.1.1

**Finding:** systemd-journald service is not active.

Checks whether the systemd-journald service is loaded and running so that system logging events are captured.

This rule fails when `systemd-journald.service` is masked, disabled, or not `RUNNING`.

**Rationale:** If systemd-journald is not running the system will not capture logging events.

#### Remediation

From the command line:

```sh
systemctl unmask systemd-journald.service
systemctl --now enable systemd-journald.service
```

Framework mappings

- **CIS Controls v8**: 8.2 Collect Audit Logs
- **NIST SP 800-53 Rev. 5**: AU-2 Event Logging; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation
- **PCI DSS v4.0.1**: 5.3.4 Enable and retain anti-malware audit logs; 6.4.1 Assess or shield public-facing web applications against known attacks; 6.4.2 Deploy an automated solution that blocks attacks on public web apps; 10.2.1.1 Record every individual user's cardholder data access; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.3 Record any access made to audit records themselves; 10.2.1.4 Record failed logical access attempts; 10.2.1.5 Record account creation, privilege elevation, and other credential changes; 10.2.1.6 Record when audit logging is initialized, started, stopped, or paused; 10.2.1.7 Record the creation or removal of system-level objects; 10.2.2 Include user, event type, date, and time in each log entry

Risk

Reliability Impact

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

### [Ensure systemd-journal-remote service is not in use](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/logging-and-auditing.html#systemd-journal-remote-service-is-not-in-use)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 6.1.1.1

**Finding:** systemd-journal-remote service is in use.

Checks that the systemd-journal-remote socket and service are masked or stopped so the host does not act as a remote journal log receiver.

This rule fails when the service unit is `loaded` (not masked) and `RUNNING`.

**Rationale:** A client configured to also receive remote logs becomes a log server and operates outside its intended boundary.

**Impact:** The host will no longer be able to receive journal logs from remote hosts.

#### Remediation

From the command line:

```sh
systemctl stop systemd-journal-remote.socket systemd-journal-remote.service
systemctl mask systemd-journal-remote.socket systemd-journal-remote.service
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure rsyslog service is enabled and active](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/logging-and-auditing.html#rsyslog-service-is-enabled-and-active)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 6.1.2

**Finding:** Rsyslog service is not enabled and active.

Checks whether the rsyslog service is enabled to start on boot and currently running so logging events are captured.

This rule fails when `rsyslog.service` is masked, disabled, or not `RUNNING`.

**Rationale:** If rsyslog is not enabled to start on boot the system will not capture logging events.

#### Remediation

From the command line:

```sh
systemctl unmask rsyslog.service
systemctl enable rsyslog.service
systemctl start rsyslog.service
```

Framework mappings

- **CIS Controls v8**: 8.2 Collect Audit Logs
- **NIST SP 800-53 Rev. 5**: AU-2 Event Logging; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation
- **PCI DSS v4.0.1**: 5.3.4 Enable and retain anti-malware audit logs; 6.4.1 Assess or shield public-facing web applications against known attacks; 6.4.2 Deploy an automated solution that blocks attacks on public web apps; 10.2.1.1 Record every individual user's cardholder data access; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.3 Record any access made to audit records themselves; 10.2.1.4 Record failed logical access attempts; 10.2.1.5 Record account creation, privilege elevation, and other credential changes; 10.2.1.6 Record when audit logging is initialized, started, stopped, or paused; 10.2.1.7 Record the creation or removal of system-level objects; 10.2.2 Include user, event type, date, and time in each log entry

Risk

Reliability Impact

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

### [Ensure rsyslog is installed](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/logging-and-auditing.html#rsyslog-is-installed)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 6.1.2

**Finding:** Rsyslog package is not installed.

Checks that the rsyslog package is installed.

This rule fails when the package is not installed.

**Rationale:** rsyslog provides connection-oriented transmission and encryption of log data, strengthening log collection and export.

**Scope:** Ubuntu 24.04 and later endpoints.

#### Remediation

From the command line:

```sh
apt install rsyslog
```

Framework mappings

- **CIS Controls v8**: 8.2 Collect Audit Logs
- **NIST SP 800-53 Rev. 5**: AU-2 Event Logging; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation
- **PCI DSS v4.0.1**: 5.3.4 Enable and retain anti-malware audit logs; 6.4.1 Assess or shield public-facing web applications against known attacks; 6.4.2 Deploy an automated solution that blocks attacks on public web apps; 10.2.1.1 Record every individual user's cardholder data access; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.3 Record any access made to audit records themselves; 10.2.1.4 Record failed logical access attempts; 10.2.1.5 Record account creation, privilege elevation, and other credential changes; 10.2.1.6 Record when audit logging is initialized, started, stopped, or paused; 10.2.1.7 Record the creation or removal of system-level objects; 10.2.2 Include user, event type, date, and time in each log entry

Risk

Reliability Impact

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

### [Ensure rsyslog-gnutls is installed](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/logging-and-auditing.html#rsyslog-gnutls-is-installed)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 6.1.2

**Finding:** rsyslog-gnutls package is not installed.

Checks that the rsyslog-gnutls package is installed.

This rule fails when the package is not installed.

**Rationale:** Traditional syslog is clear text; rsyslog-gnutls enables TLS encryption of syslog communication in transit.

**Scope:** Ubuntu 24.04 and later endpoints.

#### Remediation

From the command line:

```sh
apt install rsyslog-gnutls
```

Framework mappings

- **CIS Controls v8**: 8.2 Collect Audit Logs
- **NIST SP 800-53 Rev. 5**: AU-2 Event Logging; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation
- **PCI DSS v4.0.1**: 5.3.4 Enable and retain anti-malware audit logs; 6.4.1 Assess or shield public-facing web applications against known attacks; 6.4.2 Deploy an automated solution that blocks attacks on public web apps; 10.2.1.1 Record every individual user's cardholder data access; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.3 Record any access made to audit records themselves; 10.2.1.4 Record failed logical access attempts; 10.2.1.5 Record account creation, privilege elevation, and other credential changes; 10.2.1.6 Record when audit logging is initialized, started, stopped, or paused; 10.2.1.7 Record the creation or removal of system-level objects; 10.2.2 Include user, event type, date, and time in each log entry

Risk

Reliability Impact

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

## 6.2 System Auditing

### [Ensure auditd service is enabled and active](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/logging-and-auditing.html#auditd-service-is-enabled-and-active)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 6.2.1

**Finding:** Auditd service is not enabled and active.

Checks whether the auditd daemon is enabled to start on boot and currently running so system events are recorded.

This rule fails when `auditd.service` is masked, disabled, or not `RUNNING`.

**Rationale:** Capturing system events lets administrators determine whether unauthorized access is occurring.

#### Remediation

From the command line:

```sh
systemctl unmask auditd
systemctl enable auditd
systemctl start auditd
```

Framework mappings

- **CIS Controls v8**: 8.2 Collect Audit Logs
- **NIST SP 800-53 Rev. 5**: AU-2 Event Logging; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation
- **PCI DSS v4.0.1**: 5.3.4 Enable and retain anti-malware audit logs; 6.4.1 Assess or shield public-facing web applications against known attacks; 6.4.2 Deploy an automated solution that blocks attacks on public web apps; 10.2.1.1 Record every individual user's cardholder data access; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.3 Record any access made to audit records themselves; 10.2.1.4 Record failed logical access attempts; 10.2.1.5 Record account creation, privilege elevation, and other credential changes; 10.2.1.6 Record when audit logging is initialized, started, stopped, or paused; 10.2.1.7 Record the creation or removal of system-level objects; 10.2.2 Include user, event type, date, and time in each log entry

Risk

Reliability Impact

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

### [Ensure auditd is installed](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/logging-and-auditing.html#auditd-is-installed)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 6.2.1

**Finding:** Auditd package is not installed.

Checks that the auditd package is installed.

This rule fails when the package is not installed.

**Rationale:** Capturing system events lets administrators determine whether unauthorized access is occurring.

**Scope:** Ubuntu 24.04 and later endpoints.

#### Remediation

From the command line:

```sh
apt install auditd
```

Framework mappings

- **CIS Controls v8**: 8.5 Collect Detailed Audit Logs
- **NIST SP 800-53 Rev. 5**: AU-3 Content of Audit Records; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation; SI-4 System Monitoring
- **PCI DSS v4.0.1**: 9.4.5 Keep a log-based inventory of electronic media holding cardholder data; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.5 Record account creation, privilege elevation, and other credential changes

Risk

Reliability Impact

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

### [Ensure audispd-plugins is installed](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/logging-and-auditing.html#audispd-plugins-is-installed)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 6.2.1

**Finding:** audispd-plugins package is not installed.

Checks that the audispd-plugins package is installed.

This rule fails when the package is not installed.

**Rationale:** Capturing system events lets administrators determine whether unauthorized access is occurring.

**Scope:** Ubuntu 24.04 and later endpoints.

#### Remediation

From the command line:

```sh
apt install audispd-plugins
```

Framework mappings

- **CIS Controls v8**: 8.5 Collect Detailed Audit Logs
- **NIST SP 800-53 Rev. 5**: AU-3 Content of Audit Records; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation; SI-4 System Monitoring
- **PCI DSS v4.0.1**: 9.4.5 Keep a log-based inventory of electronic media holding cardholder data; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.5 Record account creation, privilege elevation, and other credential changes

Risk

Reliability Impact

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

## 6.3 Configure Integrity Checking

### [Ensure aide is installed](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/logging-and-auditing.html#aide-is-installed)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 6.3

**Finding:** Aide package is not installed.

Checks that the aide package is installed.

This rule fails when the package is not installed.

**Rationale:** A host-based integrity tool detects tampering with critical system files and binaries.

**Scope:** Ubuntu 24.04 and later endpoints.

#### Remediation

From the command line:

```sh
apt install aide
```

Framework mappings

- **CIS Controls v8**: 3.14 Log Sensitive Data Access
- **NIST SP 800-53 Rev. 5**: AC-6 Least Privilege; AU-2 Event Logging; AU-12 Audit Record Generation; SI-4 System Monitoring
- **PCI DSS v4.0.1**: 10.2.1.1 Record every individual user's cardholder data access

Risk

Reliability Impact

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

### [Ensure aide-common is installed](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/logging-and-auditing.html#aide-common-is-installed)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 6.3

**Finding:** aide-common package is not installed.

Checks that the aide-common package is installed.

This rule fails when the package is not installed.

**Rationale:** A host-based integrity tool detects tampering with critical system files and binaries.

**Scope:** Ubuntu 24.04 and later endpoints.

#### Remediation

From the command line:

```sh
apt install aide-common
```

Framework mappings

- **CIS Controls v8**: 3.14 Log Sensitive Data Access
- **NIST SP 800-53 Rev. 5**: AC-6 Least Privilege; AU-2 Event Logging; AU-12 Audit Record Generation; SI-4 System Monitoring
- **PCI DSS v4.0.1**: 10.2.1.1 Record every individual user's cardholder data access

Risk

Reliability Impact

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
