SV-239129r675195_rule
V-239129
SRG-OS-000341-GPOS-00132
PHTN-67-000058
CAT II
10
Open /etc/audit/auditd.conf with a text editor.
Add or change the "max_log_file_action" line as follows:
max_log_file_action = IGNORE
At the command line, execute the following command:
# service auditd reload
At the command line, execute the following command:
# grep "^max_log_file_action" /etc/audit/auditd.conf
Expected result:
max_log_file_action = IGNORE
If the output of the command does not match the expected result, this is a finding.
V-239129
False
PHTN-67-000058
At the command line, execute the following command:
# grep "^max_log_file_action" /etc/audit/auditd.conf
Expected result:
max_log_file_action = IGNORE
If the output of the command does not match the expected result, this is a finding.
M
5323