Vault - auditd-logrotate (cron.daily script)
Vault Solution · Config document · referenced from Audit logging and log shipping
The Linux audit daemon rotates its log by size, not by time, and logrotate must not touch it. This daily script makes it rotate once a day, stamps and compresses the rotated files and keeps fourteen of them, so the audit log follows the same policy as every other log. max_log_file_action = ignore in /etc/audit/auditd.conf switches the size-based rotation off.
| Item | Value |
|---|---|
| Path on the host | /etc/cron.daily/auditd-logrotate |
| Mode | executable |
| Deployed on | every server |
| Based on | Red Hat solution 661603 |
The file
#!/bin/bash # # REF: https://access.redhat.com/solutionz/661603 # export PATH=/sbin:/bin:/usr/sbin:/usr/bin FORMAT="%Y%m%d" # Customize timestamp format as desired, per `man date` # %F_%T will lead to files like: audit.log.2015-02-26_15:43:46 COMPRESS=gzip # Change to bzip2 or xz as desired KEEP=14 # Number of compressed log files to keep ROTATE_TIME=5 # Amount of time in seconds to wait for auditd to rotate its logs. Adjust this as necessary rename_and_compress_old_logs() { for file in $(find /var/log/audit/ -name 'audit.log.[0-9]'); do timestamp=$(ls -l --time-style="+${FORMAT}" ${file} | awk '{print $6}') newfile=${file%.[0-9]}.${timestamp} # Optional: remove "-v" verbose flag from next 2 lines to hide output mv -v ${file} ${newfile} ${COMPRESS} -v ${newfile} done } delete_old_compressed_logs() { # Optional: remove "-v" verbose flag to hide output rm -v $(find /var/log/audit/ -regextype posix-extended -regex '.*audit\.log\..*(xz|gz|bz2)$' | sort -n | head -n -${KEEP}) } rename_and_compress_old_logs service auditd rotate sleep $ROTATE_TIME rename_and_compress_old_logs delete_old_compressed_logs