4.1.2.6 Ensure audit system action is defined for sending errors

Information

The operating system must be configured so that the audit system takes appropriate action when there is an error sending audit records to a remote system.

Taking appropriate action when there is an error sending audit records to a remote system will minimize the possibility of losing audit records.

Solution

Configure the action the operating system takes if there is an error sending audit records to a remote system.

Uncomment the network_failure_action option in /etc/audisp/audisp-remote.conf and set it to syslog single or halt

Example: vim /etc/audisp/audisp-remote.conf

Add the line as shown in below

network_failure_action = syslog

See Also

https://workbench.cisecurity.org/benchmarks/8415

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-2, 800-53|AU-7, 800-53|AU-12, CSCv7|6.2

Plugin: Unix

Control ID: 21f7d43a6cd3166f2fc4e7753c9199530aada6d4b302307ba875ef46db42f0f5