Skip to content

1.1.2.7.1 Ensure separate partition exists for /var/log/audit

Audit#

Run the following command and verify output shows /var/log/audit is mounted:

# findmnt -kn /var/log/audit
/var/log/audit /dev/sdb ext4 rw,nosuid,nodev,noexec,relatime,seclabel

Remediation#

For new installations, during installation create a custom partition setup and specify a separate partition for /var/log/audit.

For systems that were previously installed, create a new partition and configure /etc/fstab as appropriate.