--- {{ if .Vars.ubtu24cis_level_2 }} {{ if .Vars.ubtu24cis_rule_6_2_3_13 }} command: auditd_delete_cnf: title: 6.2.3.13 | Ensure file deletion events by users are collected | Conf exec: grep delete /etc/audit/rules.d/*.rules exit-status: 0 stdout: - '/-a always,exit -F arch=b64 -S unlink,unlinkat,rename,renameat -F auid>=1000 -F auid!=(unset|4294967295|-1) -k delete/' - '/-a always,exit -F arch=b32 -S unlink,unlinkat,rename,renameat -F auid>=1000 -F auid!=(unset|4294967295|-1) -k delete/' meta: server: 2 workstation: 2 CIS_ID: - 6.2.3.13 CISv8: - 8.5 CISv8_IG1: false CISv8_IG2: true CISv8_IG3: true NIST800-53R5: - AU-12 - SC-7 auditd_delete_live: title: 6.2.3.13 | Ensure file deletion events by users are collected | Live exec: auditctl -l | grep delete exit-status: 0 stdout: - '/-a always,exit -F arch=b64 -S rename,unlink,unlinkat,renameat -F auid>=1000 -F auid!=(unset|4294967295|-1) -F key=delete/' - '/-a always,exit -F arch=b32 -S unlink,rename,unlinkat,renameat -F auid>=1000 -F auid!=(unset|4294967295|-1) -F key=delete/' meta: server: 2 workstation: 2 CIS_ID: - 6.2.3.13 CISv8: - 8.5 CISv8_IG1: false CISv8_IG2: true CISv8_IG3: true NIST800-53R5: - AU-12 - SC-7 {{ end }} {{ end }}