AZLX-23-002220 - Amazon Linux 2023 must off-load audit records onto a different system in the event the audit storage volume is full.

Information

Information stored in one location is vulnerable to accidental or incidental deletion or alteration.

Off-loading is a common process in information systems with limited audit storage capacity.

Solution

Configure Amazon Linux 2023 to off-load audit logs in the event the audit storage volume becomes full.

Add or update the following line (depending on configuration "disk_full_action" can be set to "SYSLOG" or "SINGLE" depending on configuration) in "/etc/audit/auditd.conf" file:

disk_full_action = SYSLOG

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Amazon_Linux_2023_V1R1_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4(1), CAT|II, CCI|CCI-001851, Rule-ID|SV-274107r1120309_rule, STIG-ID|AZLX-23-002220, Vuln-ID|V-274107

Plugin: Unix

Control ID: 8cea7f16d838223d9d219e82dd4c1d0bdf17a69fb2dd6a816a6fed0948f8574b