Information
RHEL 10 must take appropriate action when the internal event queue is full.
GROUP ID: V-281109RULE ID: SV-281109r1184691
The audit system must have an action set up in case the internal event queue becomes full so that no data is lost. Information stored in one location is vulnerable to accidental or incidental deletion or alteration.
Off-loading is a common process in information systems with limited audit storage capacity.
Satisfies: SRG-OS-000342-GPOS-00133, SRG-OS-000479-GPOS-00224
Solution
Configure RHEL 10 to take appropriate action when the internal event queue is full.
Edit the "/etc/audit/auditd.conf" file and add or update the "overflow_action" option:
overflow_action = syslog
Restart the audit daemon with the following command for the changes to take effect:
$ sudo service auditd restart