Information
The operating system must be configured so that the audit system takes appropriate action when there is an error sending audit records to a remote system.
Rationale:
Taking appropriate action when there is an error sending audit records to a remote system will minimize the possibility of losing audit records.
Solution
Configure the action the operating system takes if there is an error sending audit records to a remote system.
Uncomment the network_failure_action option in /etc/audisp/audisp-remote.conf and set it to syslog, single, or halt.
Example: vim /etc/audisp/audisp-remote.conf
Add the line as shown in below
network_failure_action = syslog
Notes:
This Benchmark recommendation maps to:
Red Hat Enterprise Linux 7 Security Technical Implementation Guide:
Version 2, Release: 3 Benchmark Date: 26 Apr 2019
Vul ID: V-73163
Rule ID: SV-87815r3_rule
STIG ID: RHEL-07-030321
Severity: CAT II