1.2.23 Ensure that the maximumFileSizeMegabytes argument is set to 100

Information

Audit logs are rotated upon reaching a maximum size, which is 100 MB by default.

Rationale:

OpenShift automatically rotates the log files. Retaining old log files ensures that you would have sufficient log data available for carrying out any investigation or correlation. If you have set file size of 100 MB and the number of old log files to keep as 10, you would have approximately 1 GB of log data that you could potentially use for your analysis.

Impact:

None

Solution

None. The audit-log-maxsize parameter is by default set to 100 and not supported to change.

maximumFileSizeMegabytes: 100

Default Value:

By default, auditing is enabled.

See Also

https://workbench.cisecurity.org/benchmarks/16094

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4, CSCv7|6.4

Plugin: OpenShift

Control ID: 769e0743c853145a24850942dea8c064b17c4b557773304c253441f98e00ab22