Check: 3.092
Win2k3 Audit:
3.092
(in version v6 r1.29)
Title
The system does not generate an audit event when the audit log reaches a percent full threshold. (Cat III impact)
Discussion
When the audit log reaches a given percent full, an audit event is written to the security log. The event ID is 523 and is recorded as a success audit under the category of System. This option may be especially useful if the audit logs are set to be cleared manually. A recommended setting would be 90 percent.
Check Content
Fix Text
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> “MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning” to “90” or less.
Additional Identifiers
Rule ID: SV-29728r1_rule
Vulnerability ID: V-4108
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |