
to be taken is specified in
max_log_file_action
. Possible values for
max_log_file_action
are
ignore
,
syslog
,
suspend
,
rotate
, and
keep_logs
.
ignore
tells the audit daemon to do nothing once the size limit is
reached,
syslog
tells it to issue a warning and send it to syslog, and
suspend
causes the audit daemon to stop writing logs to disk leaving the daemon itself still
alive.
rotate
triggers log rotation using the
num_logs
setting.
keep_logs
also triggers log rotation, but does not use the
num_log
setting, so always keeps
all logs.
NOTE: CAPP Environment
To keep a complete audit trail in CAPP environments, the
keep_logs
option should be used. If using a separate partition to hold your audit logs,
adjust
max_log_file
and
num_logs
to use the entire space available
on that partition. Note that the more files that have to be rotated, the
longer it takes to get back to receiving audit events.
space_left
and
space_left_action
space_left
takes a numerical value in megabytes of remaining disk space that
triggers a configurable action by the audit daemon. The action is specified in
space_left_action
. Possible values for this parameter are
ignore
,
syslog
,
,
exec
,
suspend
,
single
, and
halt
.
ignore
tells the audit daemon
to ignore the warning and do nothing,
syslog
has it issue a warning to syslog,
and
sends an e-mail to the account specified under
action_mail_acct
.
exec
plus a path to a script executes the given script. Note that it is not possible
to pass parameters to the script.
suspend
tells the audit daemon to stop writing
to disk but remain alive while
single
triggers the system to be brought down to
single user mode.
halt
triggers a full shutdown of the system.
NOTE: CAPP Environment
Make sure that
space_left
is set to a value that gives the administrator
enough time to react to the alert and allows him to free enough disk space
for the audit daemon to continue to work. Freeing disk space would involve
calling
aureport -t
and archiving the oldest logs on a separate archiving
partition or resource. The actual value for
space_left
depends on the
size of your deployment. Set
space_left_action
to
.
Understanding Linux Audit
383
Summary of Contents for LINUX ENTERPRISE DESKTOP 11
Page 1: ...SUSE Linux Enterprise Server www novell com 11 March 17 2009 Security Guide...
Page 9: ...32 7 Managing Audit Event Records Using Keys 433 33 Useful Resources 435...
Page 10: ......
Page 29: ...Part I Authentication...
Page 30: ......
Page 55: ...Figure 4 2 YaST LDAP Server Configuration LDAP A Directory Service 41...
Page 126: ......
Page 127: ...Part II Local Security...
Page 128: ......
Page 158: ......
Page 173: ...Part III Network Security...
Page 174: ......
Page 194: ......
Page 197: ...Figure 16 2 Scenario 2 Figure 16 3 Scenario 3 Configuring VPN Server 183...
Page 210: ......
Page 228: ......
Page 229: ...Part IV Confining Privileges with Novell AppArmor...
Page 230: ......
Page 274: ......
Page 300: ......
Page 328: ......
Page 340: ......
Page 342: ......
Page 386: ......
Page 387: ...Part V The Linux Audit Framework...
Page 388: ......