3.320 - The audit system must take appropriate action when the audit storage volume is full - disk_full_action

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Taking appropriate action in case of a filled audit storage volume will minimize the possibility of losing audit records.

Solution

Configure the action the operating system takes if the disk the audit records are written to becomes full.

Uncomment or edit the "disk_full_action" option in "/etc/audisp/audisp-remote.conf" and set it to "syslog", "single", or "halt", such as the following line:

disk_full_action = single

See Also

https://docs.fedoraproject.org/f28/system-administrators-guide/index.html

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-5

Plugin: Unix

Control ID: 22ac7e8789ce9e3d97f2ec450617320c5d363734904a9bf7c5bcff447840cc6f