STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 2 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← AU-5 (2) — Response to Audit Logging Process Failures

CCI-001858

Definition

Provide an alert in an organization-defined real-time-period to organization-defined personnel, roles, and/or locations when organization-defined audit failure events requiring real-time alerts occur.

Parent Control

AU-5 (2)Response to Audit Logging Process FailuresAudit and Accountability

Linked STIG Checks (115)

V-255609CAT IIIThe A10 Networks ADC must send Emergency messages to the Console, Syslog, and Monitor.A10 Networks ADC NDM Security Technical Implementation GuideV-279070CAT IIColdFusion must be configured to support integration with a third-party Security Information and Event Management (SIEM) to support notifications.Adobe ColdFusion Security Technical Implementation GuideV-268080CAT IINixOS must enable the audit daemon.Anduril NixOS Security Technical Implementation GuideV-252475CAT IIThe macOS system must provide an immediate real-time alert to the System Administrator (SA) and Information System Security Officer (ISSO), at a minimum, of all audit failure events requiring real-time alerts.Apple macOS 12 (Monterey) Security Technical Implementation GuideV-257181CAT IIThe macOS system must provide an immediate real-time alert to the System Administrator (SA) and Information System Security Officer (ISSO), at a minimum, of all audit failure events requiring real-time alerts.Apple macOS 13 (Ventura) Security Technical Implementation GuideV-268469CAT IIThe macOS system must configure audit failure notification.Apple macOS 15 (Sequoia) Security Technical Implementation GuideV-277076CAT IIThe macOS system must configure audit failure notification.Apple macOS 26 (Tahoe) Security Technical Implementation GuideV-204996CAT IIThe ALG must provide an immediate real-time alert to, at a minimum, the SCA and ISSO, of all audit failure events where the detection and/or prevention function is unable to write events to either local storage or the centralized server.Application Layer Gateway Security Requirements GuideV-222484CAT IIApplications categorized as having a moderate or high impact must provide an immediate real-time alert to the SA and ISSO (at a minimum) for all audit failure events.Application Security and Development Security Technical Implementation GuideV-204791CAT IIThe application server must provide an immediate real-time alert to authorized users of all log failure events requiring real-time alerts.Application Server Security Requirements GuideV-272632CAT IICylanceON-PREM must be configured to support integration with a third-party Security Information and Event Management (SIEM) to support notifications.Arctic Wolf CylanceON-PREM Security Technical Implementation GuideV-255962CAT IIThe Arista network device must be configured to capture all DOD auditable events.Arista MLS EOS 4.X NDM Security Technical Implementation GuideV-276014CAT IAx-OS must off-load audit records onto a different system or media than the system being audited.Axonius Federal Systems Ax-OS Security Technical Implementation GuideV-206493CAT IIIFor the host and devices within its scope of coverage, the Central Log Server must be configured to send a real-time alert to the System Administrator (SA) and Information System Security Officer (ISSO) (at a minimum) of all audit failure events, such as loss of communications with hosts and devices, or if log records are no longer being received.Central Log Server Security Requirements GuideV-239863CAT IIThe Cisco ASA must be configured to generate a real-time alert to organization-defined personnel and/or the firewall administrator in the event communication with the central audit server is lost.Cisco ASA Firewall Security Technical Implementation GuideV-239923CAT IIThe Cisco ASA must be configured to generate an immediate real-time alert of all audit failure events requiring real-time alerts.Cisco ASA NDM Security Technical Implementation GuideV-239948CAT IIThe Cisco ASA must be configured to generate an alert that can be forwarded as an alert to organization-defined personnel and/or firewall administrator of all log failure events.Cisco ASA VPN Security Technical Implementation GuideV-215692CAT IIThe Cisco router must be configured to generate an alert for all audit failure events.Cisco IOS Router NDM Security Technical Implementation GuideV-220600CAT IIThe Cisco switch must be configured to generate an alert for all audit failure events.Cisco IOS Switch NDM Security Technical Implementation GuideV-215837CAT IIThe Cisco router must be configured to generate an alert for all audit failure events.Cisco IOS XE Router NDM Security Technical Implementation GuideV-220548CAT IIThe Cisco switch must be configured to generate an alert for all audit failure events.Cisco IOS XE Switch NDM Security Technical Implementation GuideV-216534CAT IIThe Cisco router must be configured to generate an alert for all audit failure events.Cisco IOS XR Router NDM Security Technical Implementation GuideV-242594CAT IIThe Cisco ISE must generate a critical alert to be sent to the ISSO and SA (at a minimum) in the event of an audit processing failure. This is required for compliance with C2C Step 1.Cisco ISE NAC Security Technical Implementation GuideV-242595CAT IIThe Cisco ISE must provide an alert to, at a minimum, the SA and ISSO of all audit failure events where the detection and/or prevention function is unable to write events to either local storage or the centralized server. This is required for compliance with C2C Step 1.Cisco ISE NAC Security Technical Implementation GuideV-242628CAT IIThe Cisco ISE must send an alarm to one or more individuals when the monitoring collector process has an error or failure.Cisco ISE NDM Security Technical Implementation GuideV-220497CAT IIThe Cisco switch must be configured to generate an alert for all audit failure events.Cisco NX OS Switch NDM Security Technical Implementation GuideV-233171CAT IIThe container platform must provide an immediate real-time alert to the SA and ISSO, at a minimum, of all audit failure events requiring real-time alerts.Container Platform Security Requirements GuideV-233535CAT IIPostgreSQL must provide an immediate alert to appropriate support staff of all audit log failures.Crunchy Data PostgreSQL Security Technical Implementation GuideV-261920CAT IIPostgreSQL must provide an immediate real-time alert to appropriate support staff of all audit log failures.Crunchy Data Postgres 16 Security Technical Implementation GuideV-206593CAT IIThe DBMS must provide an immediate real-time alert to appropriate support staff of all audit log failures.Database Security Requirements GuideV-269791CAT IIThe Dell OS10 Switch must generate an immediate real-time alert of all audit failure events requiring real-time alerts.Dell OS10 Switch NDM Security Technical Implementation GuideV-235835CAT IILog aggregation/SIEM systems must be configured to notify SA and ISSO on Docker Engine - Enterprise audit failure events.Docker Enterprise 2.x Linux/UNIX Security Technical Implementation GuideV-224199CAT IIThe EDB Postgres Advanced Server must provide an immediate real-time alert to appropriate support staff of all audit failure events requiring real-time alerts.EDB Postgres Advanced Server v11 on Windows Security Technical Implementation GuideV-213624CAT IIThe EDB Postgres Advanced Server must provide an immediate real-time alert to appropriate support staff of all audit log failures.EDB Postgres Advanced Server v9.6 Security Technical Implementation GuideV-259280CAT IIThe EDB Postgres Advanced Server must provide an immediate real-time alert to appropriate support staff of all audit log failures.EnterpriseDB Postgres Advanced Server (EPAS) Security Technical Implementation GuideV-266075CAT IThe F5 BIG-IP appliance must generate audit records and send records to redundant central syslog servers that are separate from the appliance.F5 BIG-IP TMOS NDM Security Technical Implementation GuideV-206700CAT IIIf communication with the central audit server is lost, the firewall must generate a real-time alert to, at a minimum, the systems adminsitrator (SA) and information system security officer (ISSO).Firewall Security Requirements GuideV-233325CAT IIForescout must generate a critical alert to be sent to the Information System Security Officer (ISSO) and Systems Administrator (SA) (at a minimum) in the event of an audit processing failure. This is required for compliance with C2C Step 1.Forescout Network Access Control Security Technical Implementation GuideV-234182CAT IIThe FortiGate device must generate an immediate real-time alert of all audit failure events requiring real-time alerts.Fortinet FortiGate Firewall NDM Security Technical Implementation GuideV-234150CAT IIIf communication with the central audit server is lost, the FortiGate firewall must generate a real-time alert to, at a minimum, the SA and ISSO.Fortinet FortiGate Firewall Security Technical Implementation GuideV-203703CAT IIThe operating system must provide an immediate real-time alert to the SA and ISSO, at a minimum, of all audit failure events requiring real-time alerts.General Purpose Operating System Security Requirements GuideV-217464CAT IIThe HP FlexFabric Switch must generate an immediate real-time alert of all audit failure events requiring real-time alerts.HP FlexFabric Switch NDM Security Technical Implementation GuideV-237820CAT IISNMP must be changed from default settings and must be configured on the storage system to provide alerts of critical events that impact system security.HPE 3PAR StoreServ 3.2.x Security Technical Implementation GuideV-255276CAT IIThe HPE 3PAR OS must provide an immediate real-time alert to the System Administrator (SA) and Information System Security Officer (ISSO), at a minimum, of all audit failure events requiring real-time alerts.HPE 3PAR StoreServ 3.3.x Security Technical Implementation GuideV-283402CAT IIThe HPE Alletra Storage ArcusOS device must have an SNMPv3 user account configured.HPE Alletra Storage ArcusOS Network Device Management Security Technical Implementation GuideV-283403CAT IIThe HPE Alletra Storage ArcusOS device must be configured to collect and send SNMPv3 notifications.HPE Alletra Storage ArcusOS Network Device Management Security Technical Implementation GuideV-266952CAT IIAOS must generate an immediate real-time alert of all audit failure events requiring real-time alerts.HPE Aruba Networking AOS NDM Security Technical Implementation GuideV-268254CAT IIThe HYCU virtual appliance must generate an immediate real-time alert of all audit failure events requiring real-time alerts.HYCU Protege Security Technical Implementation GuideV-213722CAT IIDB2 must provide an immediate real-time alert to appropriate support staff of all audit failure events requiring real-time alerts.IBM DB2 V10.5 LUW Security Technical Implementation GuideV-65261CAT IIThe DataPower Gateway must provide an immediate real-time alert to, at a minimum, the SCA and ISSO, of all audit failure events where the detection and/or prevention function is unable to write events to either local storage or the centralized server.IBM DataPower ALG Security Technical Implementation GuideV-65147CAT IIIThe DataPower Gateway must generate an immediate real-time alert of all audit failure events.IBM DataPower Network Device Management Security Technical Implementation GuideV-255785CAT IIThe MQ Appliance messaging server must alert the SA and ISSO, at a minimum, in the event of a log processing failure.IBM MQ Appliance V9.0 AS Security Technical Implementation GuideV-255758CAT IIThe MQ Appliance network device must generate an immediate alert when allocated audit record storage volume reaches 75 percent of repository maximum audit record storage capacity.IBM MQ Appliance v9.0 NDM Security Technical Implementation GuideV-255843CAT IIThe WebSphere Application Server must provide an immediate real-time alert to authorized users of all log failure events requiring real-time alerts.IBM WebSphere Traditional V9.x Security Technical Implementation GuideV-223549CAT IIIBM z/OS BUFUSEWARN in the SMFPRMxx must be properly set.IBM z/OS ACF2 Security Technical Implementation GuideV-223772CAT IIIBM z/OS BUFUSEWARN in the SMFPRMxx must be properly set.IBM z/OS RACF Security Technical Implementation GuideV-55329CAT IIThe IDPS must assign a critical severity level to all audit processing failures.Intrusion Detection and Prevention Systems (IDPS) Security Requirements GuideV-55331CAT IIThe IDPS must provide an alert to, at a minimum, the system administrator and ISSO when any audit failure events occur.Intrusion Detection and Prevention Systems (IDPS) Security Requirements GuideV-206903CAT IIThe IDPS must provide an alert to, at a minimum, the system administrator and ISSO when any audit failure events occur.Intrusion Detection and Prevention Systems Security Requirements GuideV-206904CAT IIThe IDPS must assign a critical severity level to all audit processing failures.Intrusion Detection and Prevention Systems Security Requirements GuideV-258599CAT IThe ICS must be configured to send admin log data to a redundant central log server.Ivanti Connect Secure NDM Security Technical Implementation GuideV-258593CAT IIThe ICS must be configured to forward all log failure events where the detection and/or prevention function is unable to write events to local log record or send an SNMP trap that can be forwarded to the SCA and ISSO.Ivanti Connect Secure VPN Security Technical Implementation GuideV-250998CAT IIIMobileIron Sentry must generate an immediate real-time alert of all audit failure events requiring real-time alerts.Ivanti MobileIron Sentry 9.x NDM Security Technical Implementation GuideV-250998CAT IIISentry must generate an immediate real-time alert of all audit failure events requiring real-time alerts.Ivanti Sentry 9.x NDM Security Technical Implementation GuideV-253919CAT IIThe Juniper EX switch must be configured to generate an immediate real-time alert of all audit failure events requiring real-time alerts.Juniper EX Series Switches Network Device Management Security Technical Implementation GuideV-217333CAT IIThe Juniper router must be configured to generate an alert for all audit failure events.Juniper Router NDM Security Technical Implementation GuideV-66479CAT IIThe Juniper SRX Services Gateway must generate an immediate system alert message to the management console when a log processing failure is detected.Juniper SRX SG NDM Security Technical Implementation GuideV-223199CAT IIThe Juniper SRX Services Gateway must generate an immediate system alert message to the management console when a log processing failure is detected.Juniper SRX Services Gateway NDM Security Technical Implementation GuideV-213870CAT IISQL Server or software monitoring SQL Server must provide an immediate real-time alert to appropriate support staff of all audit log failures.MS SQL Server 2014 Instance Security Technical Implementation GuideV-213985CAT IISQL Server must provide an immediate real-time alert to appropriate support staff of all audit log failures.MS SQL Server 2016 Instance Security Technical Implementation GuideV-205556CAT IIThe Mainframe Product must provide an immediate real-time alert to the operations staff, system programmers, and/or security administrators, at a minimum, of all audit failure events requiring real-time alerts.Mainframe Product Security Requirements GuideV-253729CAT IIMariaDB must provide an immediate real-time alert to appropriate support staff of all audit failure events requiring real-time alerts.MariaDB Enterprise 10.x Security Technical Implementation GuideV-220382CAT IIMarkLogic Server must provide an immediate real-time alert to appropriate support staff of all audit failures.MarkLogic Server v9 Security Technical Implementation GuideV-271345CAT IISQL Server must provide an immediate real-time alert to appropriate support staff of all audit log failures.Microsoft SQL Server 2022 Instance Security Technical Implementation GuideV-221160CAT IIMongoDB must provide audit record generation for DoD-defined auditable events within all DBMS/database components.MongoDB Enterprise Advanced 3.x Security Technical Implementation GuideV-252134CAT IIMongoDB must provide audit record generation for DoD-defined auditable events within all DBMS/database components.MongoDB Enterprise Advanced 4.x Security Technical Implementation GuideV-265940CAT IIMongoDB must provide an immediate real-time alert to appropriate support staff of all audit log failures.MongoDB Enterprise Advanced 7.x Security Technical Implementation GuideV-246935CAT IIONTAP must have audit guarantee enabled.NetApp ONTAP DSC 9.x Security Technical Implementation GuideV-202100CAT IIThe network device must generate an immediate real-time alert of all audit failure events requiring real-time alerts.Network Device Management Security Requirements GuideV-254104CAT IINutanix AOS must provide an immediate warning to the SA and ISSO, at a minimum, when allocated log record storage volume reaches 75 percent of maximum log record storage capacity.Nutanix AOS 5.20.x Application Security Technical Implementation GuideV-279425CAT IINutanix Cluster Check (NCC) must be configured to provide alerts to the system administrator (SA) and information system security officer (ISSO), immediately when audit storage reaches 75 percent capacity.Nutanix Acropolis Application Server Security Technical Implementation GuideV-238453CAT IIThe DBMS must provide a real-time alert when organization-defined audit failure events occur.Oracle Database 11.2g Security Technical Implementation GuideV-237718CAT IIThe system must provide a real-time alert when organization-defined audit failure events occur.Oracle Database 12c Security Technical Implementation GuideV-270509CAT IIOracle Database must provide an immediate real-time alert to appropriate support staff of all audit log failures.Oracle Database 19c Security Technical Implementation GuideV-235176CAT IIThe MySQL Database Server 8.0 must provide an immediate real-time alert to appropriate support staff of all audit log failures.Oracle MySQL 8.0 Security Technical Implementation GuideV-228662CAT IIIThe Palo Alto Networks security platform must have alarms enabled.Palo Alto Networks NDM Security Technical Implementation GuideV-214072CAT IIPostgreSQL must provide an immediate real-time alert to appropriate support staff of all audit log failures.PostgreSQL 9.x Security Technical Implementation GuideV-273832CAT IIThe RUCKUS ICX device must off-load audit records onto a different system or media than the system being audited.RUCKUS ICX NDM Security Technical Implementation GuideV-252846CAT IIRancher MCM must allocate audit record storage and generate audit records associated with events, users, and groups.Rancher Government Solutions Multi-Cluster Manager Security Technical Implementation GuideV-257559CAT IIOpenShift must configure Alert Manger Receivers to notify SA and ISSO of all audit failure events requiring real-time alerts.Red Hat OpenShift Container Platform 4.12 Security Technical Implementation GuideV-257559CAT IIOpenShift must configure Alert Manger Receivers to notify SA and ISSO of all audit failure events requiring real-time alerts.Red Hat OpenShift Container Platform 4.x Security Technical Implementation GuideV-251198CAT IIRedis Enterprise DBMS must provide an immediate real-time alert to appropriate support staff of all audit log failures.Redis Enterprise 6.x Security Technical Implementation GuideV-219966CAT IThe audit system must alert the System Administrator (SA) if there is any type of audit failure.Solaris 11 SPARC Security Technical Implementation GuideV-219994CAT IThe audit system must alert the System Administrator (SA) if there is any type of audit failure.Solaris 11 X86 Security Technical Implementation GuideV-221626CAT IIISplunk Enterprise must notify the System Administrator (SA) and Information System Security Officer (ISSO) (at a minimum) of all audit failure events, such as loss of communications with hosts and devices, or if log records are no longer being received.Splunk Enterprise 7.x for Windows Security Technical Implementation GuideV-251670CAT IIISplunk Enterprise must notify the System Administrator (SA) and Information System Security Officer (ISSO) (at a minimum) of all audit failure events, such as loss of communications with hosts and devices, or if log records are no longer being received.Splunk Enterprise 8.x for Linux Security Technical Implementation GuideV-279266CAT IIThe Edge SWG must generate an immediate real-time alert of all audit failure events requiring real-time alerts.Symantec Edge SWG NDM Security Technical Implementation GuideV-94261CAT IISymantec ProxySG must provide an alert to, at a minimum, the SCA and ISSO of all audit failure events where the detection and/or prevention function is unable to write events to either local storage or the centralized server.Symantec ProxySG ALG Security Technical Implementation GuideV-94669CAT IIISymantec ProxySG must generate an alert to the console when a log processing failure is detected such as loss of communications with the Central Log Server or log records are no longer being sent.Symantec ProxySG NDM Security Technical Implementation GuideV-241039CAT IIA Tanium connector must be configured to send log data to an external audit log reduction-capable system and provide alerts.Tanium 7.0 Security Technical Implementation GuideV-234065CAT IIThe Tanium enterprise audit log reduction option must be configured to provide alerts based off Tanium audit data.Tanium 7.3 Security Technical Implementation GuideV-254936CAT IIThe Tanium application must provide an immediate real-time alert to the system administrator (SA) and information system security officer (ISSO), at a minimum, of all audit failure events requiring real-time alerts.Tanium 7.x Application on TanOS Security Technical Implementation GuideV-254864CAT IIThe Tanium operating system (TanOS) must provide an immediate real-time alert to the SA and ISSO, at a minimum, of all audit failure events requiring real-time alerts.Tanium 7.x Operating System on TanOS Security Technical Implementation GuideV-253794CAT IIThe Tanium application must provide an immediate real-time alert to the system administrator and information system security officer, at a minimum, of all audit failure events requiring real-time alerts.Tanium 7.x Security Technical Implementation GuideV-241160CAT IITrend Deep Security must provide an immediate real-time alert to the SA and ISSO, at a minimum, of all audit failure events requiring real-time alerts.Trend Micro Deep Security 9.x Security Technical Implementation GuideV-242245CAT IIThe Trend Micro SMS must generate an alert for all audit failure events requiring real-time alerts.Trend Micro TippingPoint NDM Security Technical Implementation GuideV-240505CAT IIThe SLES for vRealize must provide an immediate real-time alert to the SA and ISSO, at a minimum, of all audit failure events requiring real-time alerts.VMware vRealize Automation 7.x SLES Security Technical Implementation GuideV-239599CAT IIThe SLES for vRealize must provide an immediate real-time alert to the SA and ISSO, at a minimum, of all audit failure events requiring real-time alerts.VMware vRealize Operations Manager 6.x SLES Security Technical Implementation GuideV-256491CAT IIThe Photon operating system audit log must log space limit problems to syslog.VMware vSphere 7.0 vCenter Appliance Photon OS Security Technical Implementation GuideV-256609CAT II"Rsyslog" must be configured to monitor VMware Postgres logs.VMware vSphere 7.0 vCenter Appliance PostgreSQL Security Technical Implementation GuideV-256340CAT IIvCenter must provide an immediate real-time alert to the system administrator (SA) and information system security officer (ISSO), at a minimum, of all audit failure events requiring real-time alerts.VMware vSphere 7.0 vCenter Security Technical Implementation GuideV-258810CAT IIThe Photon operating system must alert the ISSO and SA in the event of an audit processing failure.VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 Security Technical Implementation GuideV-258926CAT IIThe vCenter server must provide an immediate real-time alert to the system administrator (SA) and information system security officer (ISSO), at a minimum, of all audit failure events requiring real-time alerts.VMware vSphere 8.0 vCenter Security Technical Implementation GuideV-207455CAT IIThe VMM must provide an immediate real-time alert to the SA and ISSO, at a minimum, of all audit failure events requiring real-time alerts.Virtual Machine Manager Security Requirements GuideV-207235CAT IIThe VPN Gateway must generate a log record or an SNMP trap that can be forwarded as an alert to, at a minimum, the SCA and ISSO, of all log failure events where the detection and/or prevention function is unable to write events to either local storage or the centralized server.Virtual Private Network (VPN) Security Requirements Guide