SV-239086r675066_rule
V-239086
SRG-OS-000047-GPOS-00023
PHTN-67-000014
CAT II
10
Open /etc/audit/auditd.conf with a text editor.
Ensure that the following lines are present, not duplicated, and not commented:
disk_full_action = SYSLOG
disk_error_action = SYSLOG
admin_space_left_action = SYSLOG
At the command line, execute the following command:
# service auditd reload
At the command line, execute the following commands:
# grep -E "^disk_full_action|^disk_error_action|^admin_space_left_action" /etc/audit/auditd.conf
If any of the above parameters are not set to SYSLOG or are missing, this is a finding.
V-239086
False
PHTN-67-000014
At the command line, execute the following commands:
# grep -E "^disk_full_action|^disk_error_action|^admin_space_left_action" /etc/audit/auditd.conf
If any of the above parameters are not set to SYSLOG or are missing, this is a finding.
M
5323