Cis Ubuntu1204 V110 8 1 1 1

Configure Audit Log Storage Size

cyberstrikeus Updated

File contents

8.1.1.1 Configure Audit Log Storage Size (Not Scored)

Profile Applicability

  • Level 2

Description

Configure the maximum size of the audit log file. Once the log reaches the maximum size, it will be rotated and a new log file will be started.

Rationale

It is important that an appropriate size is determined for log files so that they do not impact the system and audit data is not lost.

Audit Procedure

Using Command Line

Perform the following to determine the maximum size of the audit log files.

grep max_log_file /etc/audit/auditd.conf

Expected Result

max_log_file = <MB>

Remediation

Using Command Line

Set the max_log_file parameter in /etc/audit/auditd.conf:

max_log_file = <MB>

Note: MB is the number of MegaBytes the file can be.

Default Value

By default, auditd will max out the log files at 5MB and retain only 4 copies of them.

References

  • CIS Ubuntu 12.04 LTS Server Benchmark v1.1.0

Profile

Level 2 - Not Scored

cyberstrikeus/cyberstrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Operating_Systems/Ubuntu/cis-ubuntu-12-04-lts-server-benchmark/cis-ubuntu1204-v110-8-1-1-1 commit ee9ff7ab06

Frequently asked questions

npx skillmds@latest add cyberstrikeus/cis-ubuntu1204-v110-8-1-1-1