Ensure Sufficient Audit Log Storage (STIGs - ubuntu2204)
Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel,
n'hésitez pas à nous contacter.
Description
The auditd
service can be configured to take an action
when disk space is running low but prior to running out of space completely.
Edit the file /etc/audit/auditd.conf
. Add or modify the following line,
substituting SIZE_in_MB appropriately:
Set this value to the appropriate size in Megabytes cause the system to
notify the user of an issue.
Rationale
Notifying administrators of an impending disk space problem may allow them to
take corrective action prior to any disruption.
Shell script
The following script can be run on the host to remediate the issue.
#!/bin/bash
# Remediation is applicable only in certain platforms
if [ ! -f /.dockerenv ] && [ ! -f /run/.containerenv ] && dpkg-query --show --showformat='${db:Status-Status}\n' 'auditd' 2>/dev/null | grep -q installed; then
var_auditd_space_left='100'
grep -q "^space_left[[:space:]]*=.*$" /etc/audit/auditd.conf && \
sed -i "s/^space_left[[:space:]]*=.*$/space_left = $var_auditd_space_left/g" /etc/audit/auditd.conf || \
echo "space_left = $var_auditd_space_left" >> /etc/audit/auditd.conf
else
>&2 echo 'Remediation is not applicable, nothing was done'
fi