RHEL-06-000160 - The system must set a maximum audit log file size.

Information

The total storage for audit log files must be large enough to retain log information over the period required. This is a function of the maximum log file size and the number of logs retained.

Solution

Determine the amount of audit data (in megabytes) which should be retained in each log file. Edit the file '/etc/audit/auditd.conf'. Add or modify the following line, substituting the correct value for [STOREMB]:

max_log_file = [STOREMB]

Set the value to '6' (MB) or higher for general-purpose systems. Larger values, of course, support retention of even more audit data.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_6_V2R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-217948r603264_rule, STIG-ID|RHEL-06-000160, STIG-Legacy|SV-50434, STIG-Legacy|V-38633, Vuln-ID|V-217948

Plugin: Unix

Control ID: 0ee73d970ea00dcee749ae2b623d2bf5f4c3b8b43d82897687b580d4ec4ffb82