SV-99031r1_rule
V-88381
SRG-OS-000047-GPOS-00023
VROM-SL-000130
CAT II
10
Edit /etc/audit/auditd.conf and set the "disk_full_action", "disk_error_action", and "admin_space_left_action" parameters to "syslog" with the following commands:
# sed -i "/^[^#]*disk_full_action/ c\disk_full_action = SYSLOG" /etc/audit/auditd.conf
# sed -i "/^[^#]*disk_error_action/ c\disk_error_action = SYSLOG" /etc/audit/auditd.conf
# sed -i "/^[^#]*admin_space_left_action/ c\admin_space_left_action = SYSLOG" /etc/audit/auditd.conf
For certain systems, the need for availability outweighs the need to log all actions, and a different setting should be determined.
Verify the /etc/audit/auditd.conf has the "disk_full_action", "disk_error_action", and "admin_disk_space_left" parameters set.
# grep disk_full_action /etc/audit/auditd.conf
If the "disk_full_action" parameter is missing or set to "suspend" or "ignore", this is a finding.
# grep disk_error_action /etc/audit/auditd.conf
If the "disk_error_action" parameter is missing or set to "suspend" or "ignore", this is a finding.
# grep admin_space_left_action /etc/audit/auditd.conf
If the "admin_space_left_action" parameter is missing or set to "suspend" or "ignore", this is a finding.
V-88381
False
VROM-SL-000130
Verify the /etc/audit/auditd.conf has the "disk_full_action", "disk_error_action", and "admin_disk_space_left" parameters set.
# grep disk_full_action /etc/audit/auditd.conf
If the "disk_full_action" parameter is missing or set to "suspend" or "ignore", this is a finding.
# grep disk_error_action /etc/audit/auditd.conf
If the "disk_error_action" parameter is missing or set to "suspend" or "ignore", this is a finding.
# grep admin_space_left_action /etc/audit/auditd.conf
If the "admin_space_left_action" parameter is missing or set to "suspend" or "ignore", this is a finding.
M
3461