RHEL-06-000161 - The system must rotate audit log files that reach the maximum file size.

Information

Automatically rotating logs (by setting this to 'rotate') minimizes the chances of the system unexpectedly running out of disk space by being overwhelmed with log data. However, for systems that must never discard log data, or which use external processes to transfer it and reclaim space, 'keep_logs' can be employed.

Solution

The default action to take when the logs reach their maximum size is to rotate the log files, discarding the oldest one. To configure the action taken by 'auditd', add or correct the line in '/etc/audit/auditd.conf':

max_log_file_action = [ACTION]

Possible values for [ACTION] are described in the 'auditd.conf' man page. These include:

'ignore'
'syslog'
'suspend'
'rotate'
'keep_logs'


Set the '[ACTION]' to 'rotate' to ensure log rotation occurs. This is the default. The setting is case-insensitive.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_6_V2R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-217949r603264_rule, STIG-ID|RHEL-06-000161, STIG-Legacy|SV-50435, STIG-Legacy|V-38634, Vuln-ID|V-217949

Plugin: Unix

Control ID: 64933634314f286befa0bd7270eee22a78e43289ab68b10cdbd1564b02295bb3