1. Home
  2. Security Hardening
  3. CIS Aliyun Linux 2 L2 V1.0.0
  4. Ensure audit logs are not automatically deleted

Ensure audit logs are not automatically deleted

Details

The max_log_file_action setting determines how to handle the audit log file reaching the max file size. A value of keep_logs will rotate the logs but never delete old logs.

Rationale:

In high security contexts, the benefits of maintaining a long audit history exceed the cost of storing the audit history.

Solution

Set the following parameter in /etc/audit/auditd.conf:

max_log_file_action = keep_logs

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Audit and Accountability.This control applies to the following type of system Unix.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles