AIX must be configured so that the audit system takes appropriate action when the audit storage volume is full.
An XCCDF Rule
Description
<VulnDiscussion>Taking appropriate action in case of a filled audit storage volume will minimize the possibility of losing audit records.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
- ID
- SV-219956r958754_rule
- Severity
- Medium
- References
- Updated
Remediation - Manual Procedure
Edit the /etc/security/audit/config file and add/modify the following values:
Note: The values for "binsize" and "freespace" are the minimum required values. These values can be increased to meet organizationally defined values that exceed the listed values.
bin:
trail = /audit/trail