5.2.2.1 Ensure audit log storage size is configured

Information

Configure the maximum size of the audit log file. Once the log reaches the maximum size, it will be rotated and a new log file will be started.

An appropriate size must be determined for log files so that they do not impact the system and audit data is not lost.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Set the following parameter in /etc/security/audit_control by site policy:

filesz:2M

See Also

https://workbench.cisecurity.org/benchmarks/19044

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4, 800-53|AU-8, CSCv7|6.4

Plugin: Unix

Control ID: d1c43e428f2240e6c41fa47a89d62fc07ee8e760bd61ee888c794ac243455785