SOL-11.1-010370 - The audit system must alert the SA when the audit storage volume approaches its capacity.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version


Filling the audit storage area can result in a denial of service or system outage and can lead to events going undetected.


The root role is required.

This action applies to the global zone only. Determine the zone that you are currently securing.

# zonename

If the command output is 'global', this action applies.

Add an audit_warn alias to /etc/mail/aliases that will forward to designated system administrator(s).

# pfedit /etc/mail/aliases

Insert a line in the form:

Put the updated aliases file into service.
# newaliases

See Also

Item Details

References: CAT|II, CCI|CCI-001855, Rule-ID|SV-219965r854528_rule, STIG-ID|SOL-11.1-010370, STIG-Legacy|SV-60709, STIG-Legacy|V-47835, Vuln-ID|V-219965

Plugin: Unix

Control ID: 97352951b310acb504522ceb18306450380b77a1311c6994495e66c2c1951989