Ensure /var/log/audit Located On Separate Partition
Extend Audit Backlog Limit for the Audit Daemon
Configure a Sufficiently Large Partition for Audit Logs
The Apache web server must use a logging mechanism that is configured to allocate log record storage capacity large enough to accommodate the logging requirements of the Apache web server.
The application server must allocate log record storage capacity in accordance with organization-defined log record storage requirements.
The Arista network device must be configured to capture all DOD auditable events.
The Docker Enterprise max-size and max-file json-file drivers logging options in the daemon.json configuration file must be configured to allocate audit record storage capacity for Universal Control Plane (UCP) and Docker Trusted Registry (DTR) per the requirements set forth by the System Security Plan (SSP).
The FortiGate device must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
The HP FlexFabric Switch must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
The storage system must allocate audit record storage capacity to store at least one weeks worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
The HYCU server must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
The DataPower Gateway must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
The WebSphere Liberty Server must allocate JVM log record storage capacity in accordance with organization-defined log record storage requirements.
DB2 must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
The WebSphere Application Server must allocate JVM log record storage capacity in accordance with organization-defined log record storage requirements.
The WebSphere Application Server must allocate audit log record storage capacity in accordance with organization-defined log record storage requirements.
The Juniper router must be configured to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
For local log files, the Juniper SRX Services Gateway must allocate log storage capacity in accordance with organization-defined log record storage requirements so that the log files do not grow to a size that causes operational issues.
The mainframe product must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
Azure SQL Database must be able to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
SQL Server must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
ONTAP must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
The network device must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
Nutanix AOS must allocate audit record storage capacity to store at least one week's worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
The node that runs Prisma Cloud Compute containers must have sufficient disk space to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
Rancher MCM must allocate audit record storage and generate audit records associated with events, users, and groups.
The Tanium SQL Server RDBMS must be configured with sufficient free space to ensure audit logging is not impacted.
The Tanium application must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
The macOS system must allocate audit record storage capacity to store at least one week's worth of audit records when audit records are not immediately sent to a central audit record storage facility.
The macOS system must allocate audit record storage capacity to store at least seven days of audit records when audit records are not immediately sent to a central audit record storage facility.
The macOS system must configure audit retention to seven days.
The macOS system must configure install.log retention to 365.
The Ubuntu operating system must allocate audit record storage capacity to store at least one weeks worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
The Ubuntu operating system must allocate audit record storage capacity to store at least one weeks' worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
PostgreSQL must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
The Cisco ASA must be configured to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
The Cisco router must be configured to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
The Cisco switch must be configured to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
The Cisco ISE must limit audit record storage capacity for all locally stored logs.
The container platform must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
The EDB Postgres Advanced Server must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
The DBMS must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
The operating system must allocate audit record storage capacity to store at least one week's worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
SSMC must allocate audit record storage capacity to store at least one weeks' worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
The HPE 3PAR operating system must be configured to allocate audit record storage capacity to store at least one week of audit records, even though all audit records are immediately sent to a centralized audit record storage system (SIEM).
AIX must allocate audit record storage capacity to store at least one weeks worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
IBM z/OS SMF collection files (system MANx data sets or LOGSTREAM DASD) must have storage capacity to store at least one weeks worth of audit data.
IBM z/OS SMF collection files (system MANx datasets or LOGSTREAM DASD) must have storage capacity to store at least one weeks worth of audit data.
The ICS must be configured to allocate local audit record storage capacity in accordance with organization-defined audit record storage requirements.
The Juniper EX switch must be configured to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
MarkLogic Server must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
MariaDB must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
MongoDB must allocate audit record storage capacity in accordance with site audit record storage requirements.
The IIS 10.0 website must use a logging mechanism configured to allocate log record storage capacity large enough to accommodate the logging requirements of the IIS 10.0 website.
The IIS 10.0 web server must use a logging mechanism configured to allocate log record storage capacity large enough to accommodate the logging requirements of the IIS 10.0 web server.
The Application event log size must be configured to 32768 KB or greater.
The Security event log size must be configured to 1024000 KB or greater.
The System event log size must be configured to 32768 KB or greater.
The Security event log size must be configured to 196608 KB or greater.
Windows Server 2019 Application event log size must be configured to 32768 KB or greater.
Windows Server 2019 Security event log size must be configured to 196608 KB or greater.
Windows Server 2019 System event log size must be configured to 32768 KB or greater.
Windows Server 2022 Application event log size must be configured to 32768 KB or greater.
Windows Server 2022 Security event log size must be configured to 196608 KB or greater.
Windows Server 2022 System event log size must be configured to 32768 KB or greater.
The Oracle Linux operating system must use a separate file system for the system audit data path large enough to hold at least one week of audit data.
OL 8 must allocate audit record storage capacity to store at least one week of audit records when audit records are not immediately sent to a central audit record storage facility.
The MySQL Database Server 8.0 must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
Automation Controller must allocate log record storage capacity and shut down by default upon log failure (unless availability is an overriding concern).
Redis Enterprise DBMS must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
All audit records must generate the event results within OpenShift.
Red Hat Enterprise Linux CoreOS (RHCOS) must allocate audit record storage capacity to store at least one weeks' worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
RHEL 8 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon.
RHEL 8 must allocate audit record storage capacity to store at least one week of audit records, when audit records are not immediately sent to a central audit record storage facility.
RHEL 9 must use a separate file system for the system audit data path.
The SUSE operating system must allocate audit record storage capacity to store at least one weeks worth of audit records when audit records are not immediately sent to a central audit record storage facility.
RHEL 9 must allocate audit record storage capacity to store at least one week's worth of audit records.
RHEL 9 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon.
The SUSE operating system must allocate audit record storage capacity to store at least one week of audit records when audit records are not immediately sent to a central audit record storage facility.
The operating system must allocate audit record storage capacity.
The operating system must configure auditing to reduce the likelihood of storage capacity being exceeded.
The VMM must allocate audit record storage capacity to store at least one weeks worth of audit records when audit records are not immediately sent to a central audit record storage facility.
The ESXi host must enable a persistent log location for all locally stored logs.
Performance Charts must properly configure log sizes and rotation.
ESX Agent Manager application files must be verified for their integrity.
Lookup Service must use a logging mechanism that is configured to allocate log record storage capacity large enough to accommodate the logging requirements of the web server.
The ESXi host must allocate audit record storage capacity to store at least one week's worth of audit records.
The ESXi host must configure a persistent log location for all locally stored logs.
The Photon operating system must configure auditd to keep five rotated log files.
The Photon operating system must configure auditd to keep logging in the event max log file size is reached.
The Security Token Service application files must be verified for their integrity.
vSphere UI must use a logging mechanism that is configured to allocate log record storage capacity large enough to accommodate the logging requirements of the web server.
The Photon operating system must allocate audit record storage capacity to store audit records when audit records are not immediately sent to a central audit record storage facility.
The web server must use a logging mechanism that is configured to allocate log record storage capacity large enough to accommodate the logging requirements of the web server.
The BIG-IP appliance must be configured to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
Ubuntu 22.04 LTS must allocate audit record storage capacity to store at least one weeks' worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
Dragos Platform must allocate audit record storage retention length.
The F5 BIG-IP appliance must manage local audit storage capacity in accordance with organization-defined audit record storage requirements.
SLEM 5 must allocate audit record storage capacity to store at least one week of audit records when audit records are not immediately sent to a central audit record storage facility.
TOSS must allocate audit record storage capacity to store at least one week's worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
The NSX Manager must be configured to send logs to a central log server.