SV-213624r508024_rule
V-213624
SRG-APP-000360-DB-000320
PPS9-00-008100
CAT II
10
Install PEM and configure audit failure event alerting as documented here: http://www.enterprisedb.com/docs/en/5.0/pemgetstarted/PEM_Getting_Started_Guide.1.28.html
An example for creating an alert that ensure the audit directory does not fill up is included below, using the thin client (browser) PEM interface. Refer also to the Supplemental Procedures document, supplied with this STIG.
Open the PEM web console in a browser
- Log in
- Click on the agent for the machine to be monitored
- Select "Management | Probe Configuration"
- Select "Disk Space" and set the check interval as you like
- Select "Management | Alerting"
- Name the definition "Audit Log Full"
- Select Template "Disk Consumption Percentage"
- Set Frequency, Comparison Operator, and Thresholds (1 minute, >,
95/96/97 for example)
- Enter the Mount Point for where the audit log is
- Click Notification tab
- Click Email all alerts
- Click "Execute Script" on Monitored Server
Review Postgres Enterprise Manager (PEM) alert settings, OS, or third-party logging software settings to determine whether a real-time alert will be sent to the appropriate personnel when auditing fails for any reason.
If real-time alerts are not sent upon auditing failure, this is a finding.
V-213624
False
PPS9-00-008100
Review Postgres Enterprise Manager (PEM) alert settings, OS, or third-party logging software settings to determine whether a real-time alert will be sent to the appropriate personnel when auditing fails for any reason.
If real-time alerts are not sent upon auditing failure, this is a finding.
M
3988