The audit system must alert the SA when the audit storage volume approaches its capacity.
Severity | Group ID | Group Title | Version | Rule ID | Date | STIG Version |
|---|---|---|---|---|---|---|
| medium | V-219993 | SRG-OS-000343 | SOL-11.1-010370 | SV-219993r971542_rule | 2026-02-19 | 3 |
Description
Filling the audit storage area can result in a denial of service or system outage and can lead to events going undetected.
ℹ️ Check
This check applies to the global zone only. Determine the zone that you are currently securing.
# zonename
If the command output is "global", this check applies.
The root role is required.
Verify the presence of an audit_warn entry in /etc/mail/aliases.
# /usr/lib/sendmail -bv audit_warn
If the response is:
audit_warn... User unknown
this is a finding.
Review the output of the command and verify that the audit_warn alias notifies the appropriate users in this form:
audit_warn:user1,user2
If an appropriate user is not listed, this is a finding.
✔️ Fix
The root role is required.
This action applies to the global zone only. Determine the zone that you are currently securing.
# zonename
If the command output is "global", this action applies.
Add an audit_warn alias to /etc/mail/aliases that will forward to designated system administrator(s).
# pfedit /etc/mail/aliases
Insert a line in the form:
audit_warn:user1,user2
Put the updated aliases file into service.
# newaliases