RHEL-07-030320 - The Red Hat Enterprise Linux operating system must be configured so that the audit system takes appropriate action when the audit storage volume is full.

Information

Taking appropriate action in case of a filled audit storage volume will minimize the possibility of losing audit records.
One method of off-loading audit logs in Red Hat Enterprise Linux is with the use of the audisp-remote dameon.

Solution

Configure the action the operating system takes if the disk the audit records are written to becomes full.

Uncomment or edit the 'disk_full_action' option in '/etc/audisp/audisp-remote.conf' and set it to 'syslog', 'single', or 'halt', such as the following line:

disk_full_action = single

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_7_V3R14_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4(1), CAT|II, CCI|CCI-001851, Rule-ID|SV-204511r877390_rule, STIG-ID|RHEL-07-030320, STIG-Legacy|SV-86711, STIG-Legacy|V-72087, Vuln-ID|V-204511

Plugin: Unix

Control ID: 81710f807e622fb664ae13efdb26fdce51b3524cf055176c07f2d2cad8cc5499