1. Home
  2. Security Hardening
  3. CIS Amazon Linux V2.1.0 L2
  4. Ensure audit logs are not automatically deleted

Ensure audit logs are not automatically deleted

Details

In high security contexts, the benefits of maintaining a long audit history exceed the cost of

storing the audit history.

Solution

Set the following parameter in /etc/audit/auditd.conf-max_log_file_action = keep_logs

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Audit and Accountability.This control applies to the following type of system Unix.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles