5.2.2.1 Ensure audit log storage size is configured

Information

Configure the maximum size of the audit log file. Once the log reaches the maximum size, it will be rotated and a new log file will be started.

Rationale:

It is important that an appropriate size is determined for log files so that they do not impact the system and audit data is not lost.

Solution

Set the following parameter in /etc/audit/auditd.conf in accordance with site policy:

max_log_file = <MB>

Default Value:

max_log_file = 8

See Also

https://workbench.cisecurity.org/benchmarks/13775

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4, CSCv7|6.4

Plugin: Unix

Control ID: 3629e31cda5f379aa7e20dadae7f8d2c644bac1d4e63508c7636fd31c8da1029