The Photon operating system must immediately notify the SA and ISSO when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity.
Severity | Group ID | Group Title | Version | Rule ID | Date | STIG Version |
---|---|---|---|---|---|---|
low | V-258845 | SRG-OS-000343-GPOS-00134 | PHTN-40-000112 | SV-258845r971542_rule | 2024-07-11 | 2 |
Description |
---|
If security personnel are not notified immediately when storage volume reaches 75 percent utilization, they are unable to plan for audit record storage capacity expansion. |
ℹ️ Check |
---|
At the command line, run the following command to verify auditd is alerting when low disk space is detected: # grep '^space_left' /etc/audit/auditd.conf Expected result: space_left = 25% space_left_action = SYSLOG If the output does not match the expected result, this is a finding. |
✔️ Fix |
---|
Navigate to and open: /etc/audit/auditd.conf Ensure the "space_left" and "space_left_action" lines are uncommented and set to the following: space_left = 25% space_left_action = SYSLOG At the command line, run the following command: # pkill -SIGHUP auditd |