5.3.1.1 Configure Audit Log Storage Size

Information

Configure the maximum size of the audit log file. Once the log reaches the maximum size, it will be rotated and a new log file will be started.

Rationale:

It is important that an appropriate size is determined for log files so that they do not impact the system and audit data is not lost.

Solution

Set the max_log_file parameter in /etc/audit/auditd.conf

max_log_file = <MB>

Note: MB is the number of Megabytes the file can be.

See Also

https://workbench.cisecurity.org/files/3096

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4, CSCv6|6.3, CSCv7|6.4

Plugin: Unix

Control ID: 13e02b2861c0dd77725b752a79f6aae83167c469b3b3318821e0a5a2165178d3