SV-279568r1192085_rule
V-279568
SRG-OS-000343-GPOS-00134
NXAC-OS-000091
CAT III
10
1. For AOS, configure the audit rules.
$ sudo salt-call state.sls security/CVM/auditCVM
2. For Prism Central, configure the audit rules.
$ sudo salt-call state.sls security/PCVM/auditPCVM
3. For Files, configure the audit rules.
$ sudo salt-call state.sls security/AFS/auditAFS
4. For AHV, configure the audit rules.
$ sudo salt-call state.sls security/KVM/auditKVM
1. Verify Nutanix OS is configured to act when allocated audit record storage volume reaches 75 percent utilization using the following command.
$ sudo grep -w space_left /etc/audit/auditd.conf
space_left = 25%
If the value of the "space_left" keyword is not set to "25%", or is commented out, this is a finding.
2. Run the following command.
$ sudo grep -w space_left_action /etc/audit/auditd.conf
space_left_action = SYSLOG
If the value of the "space_left_action" is not set to "SYSLOG" or is commented out, this is a finding.
V-279568
False
NXAC-OS-000091
1. Verify Nutanix OS is configured to act when allocated audit record storage volume reaches 75 percent utilization using the following command.
$ sudo grep -w space_left /etc/audit/auditd.conf
space_left = 25%
If the value of the "space_left" keyword is not set to "25%", or is commented out, this is a finding.
2. Run the following command.
$ sudo grep -w space_left_action /etc/audit/auditd.conf
space_left_action = SYSLOG
If the value of the "space_left_action" is not set to "SYSLOG" or is commented out, this is a finding.
M
5730