The Red Hat Enterprise Linux operating system must be configured so that the audit system takes appropriate action when there is an error sending audit records to a remote system.
An XCCDF Rule
Description
Taking appropriate action when there is an error sending audit records to a remote system will minimize the possibility of losing audit records. One method of off-loading audit logs in Red Hat Enterprise Linux is with the use of the audisp-remote dameon.
- ID
- SV-204512r877390_rule
- Version
- RHEL-07-030321
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Configure the action the operating system takes if there is an error sending audit records to a remote system.
Uncomment the "network_failure_action" option in "/etc/audisp/audisp-remote.conf" and set it to "syslog", "single", or "halt".
network_failure_action = syslog