RHEL 9 must use a separate file system for the system audit data path.
An XCCDF Rule
Description
Placing "/var/log/audit" in its own partition enables better separation between audit files and other system files, and helps ensure that auditing cannot be halted due to the partition running out of space. Satisfies: SRG-OS-000341-GPOS-00132, SRG-OS-000480-GPOS-00227
- ID
- SV-257847r1044924_rule
- Version
- RHEL-09-231030
- Severity
- Low
- References
- Updated
Remediation Templates
A Manual Procedure
Migrate the system audit data path onto a separate file system.