CIS Ubuntu 14.04 LTS - 4.1.1.3 Ensure audit logs are not automatically deleted

Configure auditd to retain all audit logs by setting max_log_file_action to keep_logs

cyberstrikeus Updated

File contents

4.1.1.3 Ensure audit logs are not automatically deleted (Scored)

Profile Applicability

  • Level 2 - Server
  • Level 2 - Workstation

Description

The max_log_file_action setting determines how to handle the audit log file reaching the max file size. A value of keep_logs will rotate the logs but never delete old logs.

Rationale

In high security contexts, the benefits of maintaining a long audit history exceed the cost of storing the audit history.

Audit Procedure

Run the following command and verify output matches:

grep max_log_file_action /etc/audit/auditd.conf

Expected Result

max_log_file_action = keep_logs

Remediation

Set the following parameter in /etc/audit/auditd.conf:

max_log_file_action = keep_logs

Default Value

Not configured to keep_logs by default.

References

  1. CIS Controls v6.1 - 6.3 Ensure Audit Logging Systems Are Not Subject To Loss

Profile

  • Level 2 - Server
  • Level 2 - Workstation

cyberstrikeus/cyberstrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Operating_Systems/Ubuntu/cis-ubuntu-linux-14-04-lts-benchmark-v2/cis-ubuntu1404-v210-4-1-1-3 commit b11e47fc25

Frequently asked questions

npx skillmds@latest add cyberstrikeus/cis-ubuntu-14-04-lts-4-1-1-3-ensure-audit-logs-are-not-autom