SV-208879r603263_rule
V-208879
SRG-OS-000480
OL6-00-000160
CAT II
10
Determine the amount of audit data (in megabytes) which should be retained in each log file. Edit the file "/etc/audit/auditd.conf". Add or modify the following line, substituting the correct value for [STOREMB]:
max_log_file = [STOREMB]
Set the value to "6" (MB) or higher for general-purpose systems. Larger values, of course, support retention of even more audit data.
Inspect "/etc/audit/auditd.conf" and locate the following line to determine how much data the system will retain in each audit log file: "# grep max_log_file /etc/audit/auditd.conf"
max_log_file = 6
If the system audit data threshold hasn't been properly set up, this is a finding.
V-208879
False
OL6-00-000160
Inspect "/etc/audit/auditd.conf" and locate the following line to determine how much data the system will retain in each audit log file: "# grep max_log_file /etc/audit/auditd.conf"
max_log_file = 6
If the system audit data threshold hasn't been properly set up, this is a finding.
M
2928