8.1.1.1 Configure Audit Log Storage Size

Information

Configure the maximum size of the audit log file. Once the log reaches the maximum size, it
will be rotated and a new log file will be started.

*Rationale*

It is important that an appropriate size is determined for log files so that they do not impact
the system and audit data is not lost.

Solution

Set the max_log_file parameter in /etc/audit/auditd.confmax_log_file = <MB>
Note- MB is the number of MegaBytes the file can be.

See Also

https://benchmarks.cisecurity.org/tools2/linux/CIS_Ubuntu_12.04_LTS_Server_Benchmark_v1.1.0.pdf