SV-274107r1120309_rule
V-274107
SRG-OS-000342-GPOS-00133
AZLX-23-002220
CAT II
10
Configure Amazon Linux 2023 to off-load audit logs in the event the audit storage volume becomes full.
Add or update the following line (depending on configuration "disk_full_action" can be set to "SYSLOG" or "SINGLE" depending on configuration) in "/etc/audit/auditd.conf" file:
disk_full_action = SYSLOG
Verify Amazon Linux 2023 takes the appropriate action when the audit storage volume is full using the following command:
$ sudo grep disk_full_action /etc/audit/auditd.conf
disk_full_action = SYSLOG
If the value of the "disk_full_action" option is not "SYSLOG", "SINGLE", or "HALT", or the line is commented out, ask the system administrator to indicate how the system takes appropriate action when an audit storage volume is full. If there is no evidence of appropriate action, this is a finding.
V-274107
False
AZLX-23-002220
Verify Amazon Linux 2023 takes the appropriate action when the audit storage volume is full using the following command:
$ sudo grep disk_full_action /etc/audit/auditd.conf
disk_full_action = SYSLOG
If the value of the "disk_full_action" option is not "SYSLOG", "SINGLE", or "HALT", or the line is commented out, ask the system administrator to indicate how the system takes appropriate action when an audit storage volume is full. If there is no evidence of appropriate action, this is a finding.
M
5700