AlmaLinux OS 9 must take appropriate action when the internal event queue is full. GROUP ID: V-269511 RULE ID: SV-269511r1050394 The audit system should have an action setup in the event the internal event queue becomes full so that no data is lost.
Solution
Edit the /etc/audit/auditd.conf file and add or update the "overflow_action" option: overflow_action = SYSLOG The audit daemon must be restarted for changes to take effect.