AZLX-23-002020 - Amazon Linux 2023 must use a separate file system for the system audit data path.

Information

Placing "/var/log/audit" in its own partition enables better separation between audit files and other system files and helps ensure that auditing cannot be halted due to the partition running out of space.

Solution

Configure Amazon Linux 2023 to have a separate file system/partition for the system audit data path.

Migrate the system audit data path onto a separate partition.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Amazon_Linux_2023_V1R2_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4, CAT|III, CCI|CCI-001849, Rule-ID|SV-274068r1120192_rule, STIG-ID|AZLX-23-002020, Vuln-ID|V-274068

Plugin: Unix

Control ID: 2ed3d6c3896fd03fb6bc64c10c1af1e3a106d2419817b4d1f79b733fdc1c513e