RHEL-06-000313 - The audit system must identify staff members to receive notifications of audit log storage volume capacity issues.

Information

Email sent to the root account is typically aliased to the administrators of the system, who can take appropriate action.

Solution

The 'auditd' service can be configured to send email to a designated account in certain situations. Add or correct the following line in '/etc/audit/auditd.conf' to ensure that administrators are notified via email for those situations:

action_mail_acct = root

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_6_V2R2_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-5a., CAT|II, CCI|CCI-000139, Rule-ID|SV-218057r603264_rule, STIG-ID|RHEL-06-000313, STIG-Legacy|SV-50481, STIG-Legacy|V-38680, Vuln-ID|V-218057

Plugin: Unix

Control ID: 7c8e8c7a157f7371b3b8d86c0c10a8a2fa9bce3ac3b44a86a5b0db78c1da4eac