SV-204507r603261_rule
V-204507
SRG-OS-000342-GPOS-00133
RHEL-07-030210
CAT II
10
Edit the /etc/audisp/audispd.conf file and add or update the "overflow_action" option:
overflow_action = syslog
The audit daemon must be restarted for changes to take effect:
# service auditd restart
Verify the audisp daemon is configured to take an appropriate action when the internal queue is full:
# grep "overflow_action" /etc/audisp/audispd.conf
overflow_action = syslog
If the "overflow_action" option is not "syslog", "single", or "halt", or the line is commented out, ask the System Administrator to indicate how the audit logs are off-loaded to a different system or storage media, and to indicate what action that system takes when the internal queue is full.
If there is no evidence the system is configured to off-load audit logs to a different system or storage media or, if the configuration does not take appropriate action when the internal queue is full, this is a finding.
V-204507
False
RHEL-07-030210
Verify the audisp daemon is configured to take an appropriate action when the internal queue is full:
# grep "overflow_action" /etc/audisp/audispd.conf
overflow_action = syslog
If the "overflow_action" option is not "syslog", "single", or "halt", or the line is commented out, ask the System Administrator to indicate how the audit logs are off-loaded to a different system or storage media, and to indicate what action that system takes when the internal queue is full.
If there is no evidence the system is configured to off-load audit logs to a different system or storage media or, if the configuration does not take appropriate action when the internal queue is full, this is a finding.
M
2899