4.1.1.1 Ensure audit log storage size is configured

Information

It is important that an appropriate size is determined for log files so that they do not impact the system and audit data is not lost.

Solution

Set the following parameter in /etc/audit/auditd.conf in accordance with site policy: max_log_file = <MB>

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4, CSCv6|6.3

Plugin: Unix

Control ID: 545198cbb762385cf12f73bc410216775b8c54626943b420a2ca020c5bdd1ade