3.321 - The audit system must take appropriate action when there is an error sending audit records to a remote system.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Taking appropriate action when there is an error sending audit records to a remote system will minimize the possibility of losing audit records.

Solution

Configure the action the operating system takes if there is an error sending audit records to a remote system.

Uncomment the "network_failure_action" option in "/etc/audisp/audisp-remote.conf" and set it to "syslog", "single", or "halt".

network_failure_action = syslog

See Also

https://docs.fedoraproject.org/f28/system-administrators-guide/index.html

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-5

Plugin: Unix

Control ID: 084ca085b713ffe2d1a827163e61c34bd258e9fd392c448cf1f9388b0e1f7fbd