6.2.1.4 Ensure audit_backlog_limit is configured

Information

In the kernel-level audit subsystem, a socket buffer queue is used to hold audit events. Whenever a new audit event is received, it is logged and prepared to be added to this queue.

The kernel boot parameter audit_backlog_limit=N, with N representing the amount of messages, will ensure that a queue cannot grow beyond a certain size. If an audit event is logged which would grow the queue beyond this limit, then a failure occurs and is handled according to the system configuration

If an audit event is logged which would grow the queue beyond the audit_backlog_limit, then a failure occurs, auditd records will be lost, and potential malicious activity could go undetected.

Solution

Edit /etc/default/grub or a file in /etc/default/grub.d/ ending in .cfg and append audit_backlog_limit=N to the existing GRUB_CMDLINE_LINUX value. The recommended size for N is 8192 or larger.

Note: Files in /etc/default/grub.d/ are sourced sequentially by /etc/default/grub . A bare assignment like GRUB_CMDLINE_LINUX="audit_backlog_limit=8192" will replace any existing value (silently dropping parameters such as audit=1, quiet, splash ). Always expand the existing variable when appending.

Example:

# printf '\nGRUB_CMDLINE_LINUX="${GRUB_CMDLINE_LINUX} audit_backlog_limit=8192"\n' >> /etc/default/grub.d/40-custom.cfg

If you are applying both this recommendation and 6.2.1.3 ( audit=1 ), combine both parameters in a single assignment to avoid one overriding the other:

# printf '\nGRUB_CMDLINE_LINUX="${GRUB_CMDLINE_LINUX} audit=1 audit_backlog_limit=8192"\n' >> /etc/default/grub.d/40-custom.cfg

Run the following command to update the grub2 configuration:

# update-grub

A reboot is required for the kernel command-line parameter to take effect.

See Also

https://workbench.cisecurity.org/benchmarks/27797