An XCCDF Group - A logical subset of the XCCDF Benchmark
/var/log/audit/audit.log
auditd
/var/log/audit
/var
syslog
audispd
active
/etc/audit/plugins.d/syslog.conf
yes
$ sudo service auditd restart
/etc/audit/auditd.conf
disk_error_action = ACTION
single
exec
halt
auditd.conf
disk_full_action = ACTION
admin_space_left_action = ACTION
suspend
max_log_file_action = ACTION
ignore
rotate
keep_logs
ACTION
num_logs = NUMLOGS
space_left_action = ACTION
email
freq
local_events
log_format
ENRICHED
overflow_action
write_logs