Rule ID
SV-258175r1045310_rule
Version
V2R8
CCIs
"audispd-plugins" provides plugins for the real-time interface to the audit subsystem, "audispd". These plugins can do things like relay events to remote machines or analyze events for suspicious behavior.
Verify that RHEL 9 has the audispd-plugins package installed with the following command: $ dnf list --installed audispd-plugins Example output: audispd-plugins.x86_64 3.0.7-101.el9_0.2 If the "audispd-plugins" package is not installed, this is a finding.
The audispd-plugins package can be installed with the following command: $ sudo dnf install audispd-plugins