3.0210 - The system must take appropriate action when the audisp-remote buffer is full.

Information

Information stored in one location is vulnerable to accidental or incidental deletion or alteration.

Off-loading is a common process in information systems with limited audit storage capacity.

When the remote buffer is full, audit logs will not be collected and sent to the central log server.

Satisfies: SRG-OS-000342-GPOS-00133, SRG-OS-000479-GPOS-00224

Solution

Edit the /etc/audisp/audispd.conf file and add or update the 'overflow_action' option:

overflow_action = syslog

The audit daemon must be restarted for changes to take effect:

# service auditd restart

See Also

https://docs.fedoraproject.org/f28/system-administrators-guide/index.html

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-5, CAT|II, CCI|CCI-001851

Plugin: Unix

Control ID: 4b5e905b0f05ea5481f821f3103984e3f1269fafdb541382dc2f061c7444e886