SV-221773r603260_rule
V-221773
SRG-OS-000342-GPOS-00133
OL07-00-030321
CAT II
10
Configure the action the operating system takes if there is an error sending audit records to a remote system.
Uncomment the "network_failure_action" option in "/etc/audisp/audisp-remote.conf" and set it to "syslog", "single", or "halt".
network_failure_action = syslog
Verify the action the operating system takes if there is an error sending audit records to a remote system.
Check the action that takes place if there is an error sending audit records to a remote system with the following command:
# grep -i network_failure_action /etc/audisp/audisp-remote.conf
network_failure_action = syslog
If the value of the "network_failure_action" option is not "syslog", "single", or "halt", or the line is commented out, ask the System Administrator to indicate how the audit logs are off-loaded to a different system or storage media, and to indicate the action taken if there is an error sending audit records to the remote system.
If there is no evidence that the system is configured to off-load audit logs to a different system or storage media, or if the configuration does not take appropriate action if there is an error sending audit records to the remote system, this is a finding.
V-221773
False
OL07-00-030321
Verify the action the operating system takes if there is an error sending audit records to a remote system.
Check the action that takes place if there is an error sending audit records to a remote system with the following command:
# grep -i network_failure_action /etc/audisp/audisp-remote.conf
network_failure_action = syslog
If the value of the "network_failure_action" option is not "syslog", "single", or "halt", or the line is commented out, ask the System Administrator to indicate how the audit logs are off-loaded to a different system or storage media, and to indicate the action taken if there is an error sending audit records to the remote system.
If there is no evidence that the system is configured to off-load audit logs to a different system or storage media, or if the configuration does not take appropriate action if there is an error sending audit records to the remote system, this is a finding.
M
4089