RHEL-07-030210 - The Red Hat Enterprise Linux operating system must take appropriate action when the remote logging buffer is full.

Information

Information stored in one location is vulnerable to accidental or incidental deletion or alteration.

Off-loading is a common process in information systems with limited audit storage capacity.

One method of off-loading audit logs in Red Hat Enterprise Linux is with the use of the audisp-remote dameon. When the remote buffer is full, audit logs will not be collected and sent to the central log server.

Satisfies: SRG-OS-000342-GPOS-00133, SRG-OS-000479-GPOS-00224

Solution

Edit the /etc/audisp/audispd.conf file and add or update the 'overflow_action' option:

overflow_action = syslog

The audit daemon must be restarted for changes to take effect:

# service auditd restart

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_7_V3R15_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4(1), CAT|II, CCI|CCI-001851, Rule-ID|SV-204507r958754_rule, STIG-ID|RHEL-07-030210, STIG-Legacy|SV-95731, STIG-Legacy|V-81019, Vuln-ID|V-204507

Plugin: Unix

Control ID: eb56a5b28bafaadcc59f27b88ff54a5fd8681a3bc793834eb37df56bb554b24e