Skip to content

AlmaLinux OS 9 must allocate audit record storage capacity to store at least one week's worth of audit records.

An XCCDF Rule

Description

To ensure AlmaLinux OS 9 systems have a sufficient storage capacity in which to write the audit logs, AlmaLinux OS 9 needs to be able to allocate audit record storage capacity. The task of allocating audit record storage capacity is usually performed during initial installation of AlmaLinux OS 9.

ID
SV-269508r1050391_rule
Version
ALMA-09-052050
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Allocate enough storage capacity for at least one week of audit records when audit records are not immediately sent to a central audit record storage facility.

If audit records are stored on a partition made specifically for audit records, resize the partition with sufficient space to contain one week of audit records.

If audit records are not stored on a partition made specifically for audit records, a new partition with sufficient space will need be to be created.