RHEL-06-000511 - The audit system must take appropriate action when there are disk errors on the audit storage volume.

Information

Taking appropriate action in case of disk errors will minimize the possibility of losing audit records.

Solution

Edit the file '/etc/audit/auditd.conf'. Modify the following line, substituting [ACTION] appropriately:

disk_error_action = [ACTION]

Possible values for [ACTION] are described in the 'auditd.conf' man page. These include:

'ignore'
'syslog'
'exec'
'suspend'
'single'
'halt'


Set this to 'syslog', 'exec', 'single', or 'halt'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_6_V2R2_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-5b., CAT|II, CCI|CCI-000140, Rule-ID|SV-218094r603264_rule, STIG-ID|RHEL-06-000511, STIG-Legacy|SV-50264, STIG-Legacy|V-38464, Vuln-ID|V-218094

Plugin: Unix

Control ID: e55b7397451f8d64a262ed41f626daeaab92ee84b850640db22a763635dc8b37