The Photon operating system must configure auditd to log space limit problems to syslog.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-256529PHTN-30-000057SV-256529r971542_ruleCCI-001855medium
Description
If security personnel are not notified immediately when storage volume reaches 75 percent utilization, they are unable to plan for audit record storage capacity expansion.
STIGDate
VMware vSphere 7.0 vCenter Appliance Photon OS Security Technical Implementation Guide2024-12-16

Details

Check Text (C-256529r971542_chk)

At the command line, run the following command: # grep "^space_left " /etc/audit/auditd.conf Expected result: space_left = 75 If the output does not match the expected result, this is a finding.

Fix Text (F-60147r887260_fix)

Navigate to and open: /etc/audit/auditd.conf Ensure the "space_left" line is uncommented and set to the following: space_left = 75 At the command line, run the following commands: # killproc auditd -TERM # systemctl start auditd