Cis Ubuntu1204 V110 8 1 1 3

Keep All Auditing Information

cyberstrikeus Updated

File contents

8.1.1.3 Keep All Auditing Information (Scored)

Profile Applicability

  • Level 2

Description

Normally, auditd will hold 4 logs of maximum log file size before deleting older log files.

Rationale

In high security contexts, the benefits of maintaining a long audit history exceed the cost of storing the audit history.

Audit Procedure

Using Command Line

Perform the following to determine if audit logs are retained.

grep max_log_file_action /etc/audit/auditd.conf

Expected Result

max_log_file_action = keep_logs

Remediation

Using Command Line

Add the following line to the /etc/audit/auditd.conf file:

max_log_file_action = keep_logs

Default Value

By default, auditd retains only 4 copies of log files.

References

  • CIS Ubuntu 12.04 LTS Server Benchmark v1.1.0

Profile

Level 2 - Scored

cyberstrikeus/cyberstrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Operating_Systems/Ubuntu/cis-ubuntu-12-04-lts-server-benchmark/cis-ubuntu1204-v110-8-1-1-3 commit 23decb71b9

Frequently asked questions

npx skillmds@latest add cyberstrikeus/cis-ubuntu1204-v110-8-1-1-3