RHEL-06-000510 - The audit system must take appropriate action when the audit storage volume is full.

Information

Taking appropriate action in case of a filled audit storage volume will minimize the possibility of losing audit records.

Solution

The 'auditd' service can be configured to take an action when disk space starts to run low. Edit the file '/etc/audit/auditd.conf'. Modify the following line, substituting [ACTION] appropriately:

disk_full_action = [ACTION]

Possible values for [ACTION] are described in the 'auditd.conf' man page. These include:

'ignore'
'syslog'
'exec'
'suspend'
'single'
'halt'


Set this to 'syslog', 'exec', 'single', or 'halt'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_6_V2R2_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-5b., CAT|II, CCI|CCI-000140, Rule-ID|SV-218093r603264_rule, STIG-ID|RHEL-06-000510, STIG-Legacy|SV-50268, STIG-Legacy|V-38468, Vuln-ID|V-218093

Plugin: Unix

Control ID: 44dbde3b182003c41a006cc30fb7ad9cb4b77028e1478ae640c0801b9d1bdfce