RHEL-06-000159 - The system must retain enough rotated audit logs to cover the required log retention period.

Information

The total storage for audit log files must be large enough to retain log information over the period required. This is a function of the maximum log file size and the number of logs retained.

Solution

Determine how many log files 'auditd' should retain when it rotates logs. Edit the file '/etc/audit/auditd.conf'. Add or modify the following line, substituting [NUMLOGS] with the correct value:

num_logs = [NUMLOGS]

Set the value to 5 for general-purpose systems. Note that values less than 2 result in no log rotation.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_6_V2R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-217947r603264_rule, STIG-ID|RHEL-06-000159, STIG-Legacy|SV-50437, STIG-Legacy|V-38636, Vuln-ID|V-217947

Plugin: Unix

Control ID: d35e5f034b67b88dc127dd35164663c79107c534b69c74da607ab26d9fcefd4c