4.1.2.6 Ensure audit system action is defined for sending errors

Information

The operating system must be configured so that the audit system takes appropriate action when there is an error sending audit records to a remote system.

Rationale:

Taking appropriate action when there is an error sending audit records to a remote system will minimize the possibility of losing audit records.

Solution

Configure the action the operating system takes if there is an error sending audit records to a remote system.
Uncomment the network_failure_action option in /etc/audisp/audisp-remote.conf and set it to syslog, single, or halt.
Example: vim /etc/audisp/audisp-remote.conf
Add the line as shown in below

network_failure_action = syslog

See Also

https://workbench.cisecurity.org/files/3636

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4(1), CCI|CCI-001851, CSCv7|6.2, Rule-ID|SV-204512r603261_rule, STIG-ID|RHEL-07-030321

Plugin: Unix

Control ID: cf535aa2cbf1d1a490d604d94016fd2df58a9393245b1f26869d2c185290993b