4.6 Ensure audit system action is defined for sending errors

Information

The operating system must be configured so that the audit system takes appropriate action when there is an error sending audit records to a remote system.

Rationale:

Taking appropriate action when there is an error sending audit records to a remote system will minimize the possibility of losing audit records.

Solution

Configure the action the operating system takes if there is an error sending audit records to a remote system.
Uncomment the network_failure_action option in /etc/audisp/audisp-remote.conf and set it to syslog, single, or halt.
Example: vim /etc/audisp/audisp-remote.conf
Add the line as shown in below

network_failure_action = syslog

Notes:

This Benchmark recommendation maps to:

Red Hat Enterprise Linux 7 Security Technical Implementation Guide:

Version 2, Release: 3 Benchmark Date: 26 Apr 2019



Vul ID: V-73163

Rule ID: SV-87815r3_rule

STIG ID: RHEL-07-030321

Severity: CAT II

See Also

https://workbench.cisecurity.org/files/2688

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-5b.

Plugin: Unix

Control ID: c03ff076ea76fb46c9451b3887a9ed55f7388002d95b6a01f6887d99aec2d5e9