SV-99319r1_rule
V-88669
SRG-OS-000344-GPOS-00135
VROM-SL-001045
CAT II
10
Set the "space_left_action" parameter to the valid setting "SYSLOG", by running the following command:
# sed -i "/^[^#]*space_left_action/ c\admin_space_left_action = SYSLOG" /etc/audit/auditd.conf
Restart the audit service:
# service auditd restart
Check "/etc/audit/auditd.conf" file for the "space_left_action" parameter with the following command:
# cat /etc/audit/auditd.conf | grep space_left_action
If the "space_left_action" parameter is missing, set to "ignore", set to "suspend", set to "single", set to "halt", or is blank, this is a finding
Expected Result:
space_left_action = SYSLOG
Notes:
If the "space_left_action" parameter is set to "exec" the system executes a designated script.
If this script informs the SA of the event, this is not a finding.
If the "space_left_action" parameter is set to "email" and the "action_mail_acct" parameter is not set to the email address of the system administrator, this is a finding.
The "action_mail_acct" parameter, if missing, defaults to "root". Note that if the email address of the system administrator is on a remote system "sendmail" must be available.
V-88669
False
VROM-SL-001045
Check "/etc/audit/auditd.conf" file for the "space_left_action" parameter with the following command:
# cat /etc/audit/auditd.conf | grep space_left_action
If the "space_left_action" parameter is missing, set to "ignore", set to "suspend", set to "single", set to "halt", or is blank, this is a finding
Expected Result:
space_left_action = SYSLOG
Notes:
If the "space_left_action" parameter is set to "exec" the system executes a designated script.
If this script informs the SA of the event, this is not a finding.
If the "space_left_action" parameter is set to "email" and the "action_mail_acct" parameter is not set to the email address of the system administrator, this is a finding.
The "action_mail_acct" parameter, if missing, defaults to "root". Note that if the email address of the system administrator is on a remote system "sendmail" must be available.
M
3461