3.330 - The system must immediately notify the SA and ISSO when allocated audit record storage volume reaches 75%.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

If security personnel are not notified immediately when storage volume reaches 75 percent utilization, they are unable to plan for audit record storage capacity expansion.

Solution

Configure the operating system to immediately notify the SA and ISSO (at a minimum) when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity.

Check the system configuration to determine the partition the audit records are being written to:

# grep log_file /etc/audit/auditd.conf

Determine the size of the partition that audit records are written to (with the example being "/var/log/audit/"):

# df -h /var/log/audit/

Set the value of the "space_left" keyword in "/etc/audit/auditd.conf" to 75 percent of the partition size.

See Also

https://docs.fedoraproject.org/f28/system-administrators-guide/index.html

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-5(1)

Plugin: Unix

Control ID: 5e0075dd96cd294050cc8559d2eead03c839610d1837e2835927b5fa16ccdff3