Link to home
Start Free TrialLog in
Avatar of abuhaneef
abuhaneefFlag for United States of America

asked on

Audit Log Retention for One Year

What changes should I make to the auditd.conf in order to retain audit logs for one year?  System is Centos 6.2.  Should I change the "max_log_file = SIZE"?  What about "max_log_file_action = keep_logs"? Does this keep logs indefinitely?
Avatar of David VanZandt
David VanZandt
Flag of United States of America image

Regrets for answering a question with a question, but it begs the obvious:  consider moving the logs periodically onto off-line storage (such as tape) rather than wasting primary resources.  And, under what conditions would you be called upon to review a year old log?

This is not my field so this link may not be useful, but consider https://www.experts-exchange.com/questions/27654713/TSM-Client-retention-backups-for-1-year-retention.html.
Avatar of abuhaneef

ASKER

There is no tape drive or external storage device available.  Review of logs may become necessary in case of security breach, system malfunction, etc.
ASKER CERTIFIED SOLUTION
Avatar of David VanZandt
David VanZandt
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial