The Photon operating system must configure auditd to log space limit problems to syslog.
An XCCDF Rule
Description
If security personnel are not notified immediately when storage volume reaches 75 percent utilization, they are unable to plan for audit record storage capacity expansion.
- ID
- SV-256529r971542_rule
- Version
- PHTN-30-000057
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Navigate to and open:
/etc/audit/auditd.conf
Ensure the "space_left" line is uncommented and set to the following: