Blame SOURCES/scap-security-guide-0.1.58-RHEL_08_030730-PR_7323.patch

362bfa
From 2f4ddb4297f2a14e2bde3b32f76347e2bbe2cb2d Mon Sep 17 00:00:00 2001
362bfa
From: Matthew Burket <mburket@redhat.com>
362bfa
Date: Thu, 19 Aug 2021 09:47:42 -0500
362bfa
Subject: [PATCH] Add new rule for RHEL-07-030330 and RHEL-08-030730
362bfa
362bfa
This new rule is copy of auditd_data_retention_space_left, but
362bfa
setup to allow for percentages.
362bfa
---
362bfa
 .../auditd_data_retention_space_left/rule.yml |  2 -
362bfa
 .../ansible/shared.yml                        | 15 ++++++
362bfa
 .../bash/shared.sh                            |  7 +++
362bfa
 .../oval/shared.xml                           | 32 +++++++++++++
362bfa
 .../rule.yml                                  | 47 +++++++++++++++++++
362bfa
 .../tests/no_percent_sign.fail.sh             |  6 +++
362bfa
 .../space_left_greater_than_minimum.pass.sh   |  6 +++
362bfa
 .../tests/space_left_minimum_value.pass.sh    |  6 +++
362bfa
 .../tests/space_left_not_enough.fail.sh       |  6 +++
362bfa
 .../tests/space_left_not_there.fail.sh        |  6 +++
362bfa
 .../var_auditd_space_left_percentage.var      | 15 ++++++
362bfa
 products/rhel7/profiles/stig.profile          |  3 +-
362bfa
 products/rhel8/profiles/stig.profile          |  7 +--
362bfa
 shared/references/cce-redhat-avail.txt        |  2 -
362bfa
 .../data/profile_stability/rhel8/stig.profile |  3 +-
362bfa
 .../profile_stability/rhel8/stig_gui.profile  |  3 +-
362bfa
 16 files changed, 156 insertions(+), 10 deletions(-)
362bfa
 create mode 100644 linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/ansible/shared.yml
362bfa
 create mode 100644 linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/bash/shared.sh
362bfa
 create mode 100644 linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/oval/shared.xml
362bfa
 create mode 100644 linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/rule.yml
362bfa
 create mode 100644 linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/tests/no_percent_sign.fail.sh
362bfa
 create mode 100644 linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/tests/space_left_greater_than_minimum.pass.sh
362bfa
 create mode 100644 linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/tests/space_left_minimum_value.pass.sh
362bfa
 create mode 100644 linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/tests/space_left_not_enough.fail.sh
362bfa
 create mode 100644 linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/tests/space_left_not_there.fail.sh
362bfa
 create mode 100644 linux_os/guide/system/auditing/configure_auditd_data_retention/var_auditd_space_left_percentage.var
362bfa
362bfa
diff --git a/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left/rule.yml b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left/rule.yml
362bfa
index 7fd0470df8..a652d15d0d 100644
362bfa
--- a/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left/rule.yml
362bfa
+++ b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left/rule.yml
362bfa
@@ -39,8 +39,6 @@ references:
362bfa
     pcidss: Req-10.7
362bfa
     srg: SRG-OS-000343-GPOS-00134
362bfa
     stigid@ol7: OL07-00-030330
362bfa
-    stigid@rhel7: RHEL-07-030330
362bfa
-    stigid@rhel8: RHEL-08-030730
362bfa
     stigid@sle12: SLES-12-020030
362bfa
     stigid@sle15: SLES-15-030700
362bfa
     stigid@ubuntu2004: UBTU-20-010217
362bfa
diff --git a/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/ansible/shared.yml b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/ansible/shared.yml
362bfa
new file mode 100644
362bfa
index 0000000000..ea52773bd3
362bfa
--- /dev/null
362bfa
+++ b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/ansible/shared.yml
362bfa
@@ -0,0 +1,15 @@
362bfa
+# platform = multi_platform_all
362bfa
+# reboot = false
362bfa
+# strategy = restrict
362bfa
+# complexity = low
362bfa
+# disruption = low
362bfa
+{{{ ansible_instantiate_variables("var_auditd_space_left_percentage") }}}
362bfa
+
362bfa
+- name: Configure auditd space_left on Low Disk Space
362bfa
+  lineinfile:
362bfa
+    dest: /etc/audit/auditd.conf
362bfa
+    line: "space_left = {{ var_auditd_space_left_percentage }}%"
362bfa
+    regexp: '^\s*space_left\s*=\s*.*$'
362bfa
+    state: present
362bfa
+    create: yes
362bfa
+  #notify: reload auditd
362bfa
diff --git a/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/bash/shared.sh b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/bash/shared.sh
362bfa
new file mode 100644
362bfa
index 0000000000..6cc3e9ecbe
362bfa
--- /dev/null
362bfa
+++ b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/bash/shared.sh
362bfa
@@ -0,0 +1,7 @@
362bfa
+# platform = multi_platform_all
362bfa
+. /usr/share/scap-security-guide/remediation_functions
362bfa
+{{{ bash_instantiate_variables("var_auditd_space_left_percentage") }}}
362bfa
+
362bfa
+grep -q "^space_left[[:space:]]*=.*$" /etc/audit/auditd.conf && \
362bfa
+  sed -i "s/^space_left[[:space:]]*=.*$/space_left = $var_auditd_space_left_percentage%/g" /etc/audit/auditd.conf || \
362bfa
+  echo "space_left = $var_auditd_space_left_percentage%" >> /etc/audit/auditd.conf
362bfa
diff --git a/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/oval/shared.xml b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/oval/shared.xml
362bfa
new file mode 100644
362bfa
index 0000000000..2fcd222d29
362bfa
--- /dev/null
362bfa
+++ b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/oval/shared.xml
362bfa
@@ -0,0 +1,32 @@
362bfa
+<def-group>
362bfa
+  <definition class="compliance" id="{{{ rule_id }}}" version="2">
362bfa
+    {{{ oval_metadata("space_left setting in /etc/audit/auditd.conf is set to at least a certain value") }}}
362bfa
+
362bfa
+    <criteria>
362bfa
+        <criterion comment="space_left setting in auditd.conf" test_ref="test_auditd_data_retention_space_left_percentage" />
362bfa
+    </criteria>
362bfa
+
362bfa
+  </definition>
362bfa
+
362bfa
+  <ind:textfilecontent54_test check="all" comment="admin space left action " id="test_auditd_data_retention_space_left_percentage" version="1">
362bfa
+    <ind:object object_ref="object_auditd_data_retention_space_left_percentage" />
362bfa
+    <ind:state state_ref="state_auditd_data_retention_space_left_percentage" />
362bfa
+  </ind:textfilecontent54_test>
362bfa
+
362bfa
+  <ind:textfilecontent54_object id="object_auditd_data_retention_space_left_percentage" version="2">
362bfa
+    <ind:filepath>/etc/audit/auditd.conf</ind:filepath>
362bfa
+    
362bfa
+    
362bfa
+    <ind:pattern operation="pattern match">^[\s]*space_left[\s]+=[\s]+(\d+)%[\s]*$</ind:pattern>
362bfa
+    <ind:instance datatype="int">1</ind:instance>
362bfa
+  </ind:textfilecontent54_object>
362bfa
+
362bfa
+
362bfa
+  <ind:textfilecontent54_state id="state_auditd_data_retention_space_left_percentage" version="1">
362bfa
+    <ind:subexpression operation="greater than or equal" var_ref="var_auditd_space_left_percentage" datatype="int" />
362bfa
+  </ind:textfilecontent54_state>
362bfa
+
362bfa
+  <external_variable comment="audit space_left setting" datatype="int" id="var_auditd_space_left_percentage" version="1" />
362bfa
+
362bfa
+
362bfa
+</def-group>
362bfa
diff --git a/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/rule.yml b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/rule.yml
362bfa
new file mode 100644
362bfa
index 0000000000..ea9d9fcc6b
362bfa
--- /dev/null
362bfa
+++ b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/rule.yml
362bfa
@@ -0,0 +1,47 @@
362bfa
+documentation_complete: true
362bfa
+
362bfa
+prodtype:  fedora,rhel7,rhel8,rhel9
362bfa
+
362bfa
+title: 'Configure auditd space_left on Low Disk Space'
362bfa
+
362bfa
+description: |-
362bfa
+    The <tt>auditd</tt> service can be configured to take an action
362bfa
+    when disk space is running low but prior to running out of space completely.
362bfa
+    Edit the file <tt>/etc/audit/auditd.conf</tt>. Add or modify the following line,
362bfa
+    substituting PERCENTAGE appropriately:
362bfa
+    
space_left = PERCENTAGE%
362bfa
+    Set this value to at least 25 to cause the system to
362bfa
+    notify the user of an issue.
362bfa
+
362bfa
+rationale: |-
362bfa
+    Notifying administrators of an impending disk space problem may allow them to
362bfa
+    take corrective action prior to any disruption.
362bfa
+
362bfa
+severity: medium
362bfa
+
362bfa
+identifiers:
362bfa
+    cce@rhel7: CCE-86056-9
362bfa
+    cce@rhel8: CCE-86055-1
362bfa
+
362bfa
+references:
362bfa
+    cis-csc: 1,11,12,13,14,15,16,19,2,3,4,5,6,7,8
362bfa
+    cobit5: APO11.04,APO12.06,APO13.01,BAI03.05,BAI04.04,BAI08.02,DSS02.02,DSS02.04,DSS02.07,DSS03.01,DSS05.04,DSS05.07,MEA02.01
362bfa
+    disa: CCI-001855
362bfa
+    isa-62443-2009: 4.2.3.10,4.3.3.3.9,4.3.3.5.8,4.3.4.4.7,4.3.4.5.6,4.3.4.5.7,4.3.4.5.8,4.4.2.1,4.4.2.2,4.4.2.4
362bfa
+    isa-62443-2013: 'SR 2.10,SR 2.11,SR 2.12,SR 2.8,SR 2.9,SR 6.1,SR 7.1,SR 7.2'
362bfa
+    iso27001-2013: A.12.1.3,A.12.4.1,A.12.4.2,A.12.4.3,A.12.4.4,A.12.7.1,A.16.1.4,A.16.1.5,A.16.1.7,A.17.2.1
362bfa
+    nist: AU-5(b),AU-5(2),AU-5(1),AU-5(4),CM-6(a)
362bfa
+    nist-csf: DE.AE-3,DE.AE-5,PR.DS-4,PR.PT-1,RS.AN-1,RS.AN-4
362bfa
+    pcidss: Req-10.7
362bfa
+    srg: SRG-OS-000343-GPOS-00134
362bfa
+    stigid@rhel7: RHEL-07-030330
362bfa
+    stigid@rhel8: RHEL-08-030730
362bfa
+    vmmsrg: SRG-OS-000343-VMM-001240
362bfa
+
362bfa
+ocil_clause: 'the system is not configured with a specific percentage to notify administrators of an issue'
362bfa
+
362bfa
+ocil: |-
362bfa
+    Inspect <tt>/etc/audit/auditd.conf</tt> and locate the following line to
362bfa
+    determine if the system is configured correctly:
362bfa
+    
space_left PERCENTAGE%
362bfa
+
362bfa
diff --git a/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/tests/no_percent_sign.fail.sh b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/tests/no_percent_sign.fail.sh
362bfa
new file mode 100644
362bfa
index 0000000000..2e90ce1d7b
362bfa
--- /dev/null
362bfa
+++ b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/tests/no_percent_sign.fail.sh
362bfa
@@ -0,0 +1,6 @@
362bfa
+#!/bin/bash
362bfa
+# variables = var_auditd_space_left_percentage=25
362bfa
+
362bfa
+. $SHARED/auditd_utils.sh
362bfa
+prepare_auditd_test_enviroment
362bfa
+set_parameters_value /etc/audit/auditd.conf "space_left" "25"
362bfa
diff --git a/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/tests/space_left_greater_than_minimum.pass.sh b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/tests/space_left_greater_than_minimum.pass.sh
362bfa
new file mode 100644
362bfa
index 0000000000..135d6e4258
362bfa
--- /dev/null
362bfa
+++ b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/tests/space_left_greater_than_minimum.pass.sh
362bfa
@@ -0,0 +1,6 @@
362bfa
+#!/bin/bash
362bfa
+# variables = var_auditd_space_left_percentage=25
362bfa
+
362bfa
+. $SHARED/auditd_utils.sh
362bfa
+prepare_auditd_test_enviroment
362bfa
+set_parameters_value /etc/audit/auditd.conf "space_left" "35%"
362bfa
diff --git a/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/tests/space_left_minimum_value.pass.sh b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/tests/space_left_minimum_value.pass.sh
362bfa
new file mode 100644
362bfa
index 0000000000..10d652e80e
362bfa
--- /dev/null
362bfa
+++ b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/tests/space_left_minimum_value.pass.sh
362bfa
@@ -0,0 +1,6 @@
362bfa
+#!/bin/bash
362bfa
+# variables = var_auditd_space_left_percentage=25
362bfa
+
362bfa
+. $SHARED/auditd_utils.sh
362bfa
+prepare_auditd_test_enviroment
362bfa
+set_parameters_value /etc/audit/auditd.conf "space_left" "25%"
362bfa
diff --git a/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/tests/space_left_not_enough.fail.sh b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/tests/space_left_not_enough.fail.sh
362bfa
new file mode 100644
362bfa
index 0000000000..0bf7694b15
362bfa
--- /dev/null
362bfa
+++ b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/tests/space_left_not_enough.fail.sh
362bfa
@@ -0,0 +1,6 @@
362bfa
+#!/bin/bash
362bfa
+# variables = var_auditd_space_left_percentage=25
362bfa
+
362bfa
+. $SHARED/auditd_utils.sh
362bfa
+prepare_auditd_test_enviroment
362bfa
+set_parameters_value /etc/audit/auditd.conf "space_left" "15%"
362bfa
diff --git a/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/tests/space_left_not_there.fail.sh b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/tests/space_left_not_there.fail.sh
362bfa
new file mode 100644
362bfa
index 0000000000..34ac5595c6
362bfa
--- /dev/null
362bfa
+++ b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_data_retention_space_left_percentage/tests/space_left_not_there.fail.sh
362bfa
@@ -0,0 +1,6 @@
362bfa
+#!/bin/bash
362bfa
+# variables = var_auditd_space_left_percentage=25
362bfa
+
362bfa
+. $SHARED/auditd_utils.sh
362bfa
+prepare_auditd_test_enviroment
362bfa
+delete_parameter /etc/audit/auditd.conf "space_left"
362bfa
diff --git a/linux_os/guide/system/auditing/configure_auditd_data_retention/var_auditd_space_left_percentage.var b/linux_os/guide/system/auditing/configure_auditd_data_retention/var_auditd_space_left_percentage.var
362bfa
new file mode 100644
362bfa
index 0000000000..427a1d4bfa
362bfa
--- /dev/null
362bfa
+++ b/linux_os/guide/system/auditing/configure_auditd_data_retention/var_auditd_space_left_percentage.var
362bfa
@@ -0,0 +1,15 @@
362bfa
+documentation_complete: true
362bfa
+
362bfa
+title: 'The percentage remaining in disk space before prompting space_left_action'
362bfa
+
362bfa
+description: 'The setting for space_left as a percentage in /etc/audit/auditd.conf'
362bfa
+
362bfa
+type: number
362bfa
+
362bfa
+interactive: true
362bfa
+
362bfa
+options:
362bfa
+    25pc: 25
362bfa
+    50pc: 50
362bfa
+    75pc: 75
362bfa
+    default: 25
362bfa
diff --git a/products/rhel7/profiles/stig.profile b/products/rhel7/profiles/stig.profile
362bfa
index 9ca1360005..67e22982cd 100644
362bfa
--- a/products/rhel7/profiles/stig.profile
362bfa
+++ b/products/rhel7/profiles/stig.profile
362bfa
@@ -50,6 +50,7 @@ selections:
362bfa
     - var_removable_partition=dev_cdrom
362bfa
     - var_auditd_action_mail_acct=root
362bfa
     - var_auditd_space_left_action=email
362bfa
+    - var_auditd_space_left_percentage=25pc
362bfa
     - var_accounts_user_umask=077
362bfa
     - var_password_pam_retry=3
362bfa
     - var_accounts_max_concurrent_login_sessions=10
362bfa
@@ -178,8 +179,8 @@ selections:
362bfa
     - auditd_audispd_configure_remote_server
362bfa
     - auditd_audispd_encrypt_sent_records
362bfa
     - auditd_audispd_disk_full_action
362bfa
-    - auditd_data_retention_space_left
362bfa
     - auditd_data_retention_space_left_action
362bfa
+    - auditd_data_retention_space_left_percentage
362bfa
     - auditd_data_retention_action_mail_acct
362bfa
     - audit_rules_suid_privilege_function
362bfa
     - audit_rules_dac_modification_chown
362bfa
diff --git a/products/rhel8/profiles/stig.profile b/products/rhel8/profiles/stig.profile
362bfa
index 36f384621a..10dbc1501b 100644
362bfa
--- a/products/rhel8/profiles/stig.profile
362bfa
+++ b/products/rhel8/profiles/stig.profile
362bfa
@@ -65,7 +65,7 @@ selections:
362bfa
     - var_auditd_action_mail_acct=root
362bfa
     - var_time_service_set_maxpoll=18_hours
362bfa
     - var_accounts_maximum_age_login_defs=60
362bfa
-    - var_auditd_space_left=250MB
362bfa
+    - var_auditd_space_left_percentage=25pc
362bfa
     - var_auditd_space_left_action=email
362bfa
     - var_auditd_disk_error_action=halt
362bfa
     - var_auditd_max_log_file_action=syslog
362bfa
@@ -922,8 +922,9 @@ selections:
362bfa
     - rsyslog_encrypt_offload_actionsendstreamdriverauthmode
362bfa
 
362bfa
     # RHEL-08-030730
362bfa
-    # this rule expects configuration in MB instead percentage as how STIG demands
362bfa
-    # - auditd_data_retention_space_left
362bfa
+    - auditd_data_retention_space_left_percentage
362bfa
+
362bfa
+    # RHEL-08-030731
362bfa
     - auditd_data_retention_space_left_action
362bfa
 
362bfa
     # RHEL-08-030740
362bfa
diff --git a/shared/references/cce-redhat-avail.txt b/shared/references/cce-redhat-avail.txt
362bfa
index 6c33c2e85f..fcb8125ca4 100644
362bfa
--- a/shared/references/cce-redhat-avail.txt
362bfa
+++ b/shared/references/cce-redhat-avail.txt
362bfa
@@ -170,8 +170,6 @@ CCE-86051-0
362bfa
 CCE-86052-8
362bfa
 CCE-86053-6
362bfa
 CCE-86054-4
362bfa
-CCE-86055-1
362bfa
-CCE-86056-9
362bfa
 CCE-86057-7
362bfa
 CCE-86058-5
362bfa
 CCE-86059-3
362bfa
diff --git a/tests/data/profile_stability/rhel8/stig.profile b/tests/data/profile_stability/rhel8/stig.profile
362bfa
index f3e6c4fa1a..09a5bc3174 100644
362bfa
--- a/tests/data/profile_stability/rhel8/stig.profile
362bfa
+++ b/tests/data/profile_stability/rhel8/stig.profile
362bfa
@@ -140,6 +140,7 @@ selections:
362bfa
 - auditd_data_retention_action_mail_acct
362bfa
 - auditd_data_retention_max_log_file_action
362bfa
 - auditd_data_retention_space_left_action
362bfa
+- auditd_data_retention_space_left_percentage
362bfa
 - auditd_local_events
362bfa
 - auditd_log_format
362bfa
 - auditd_name_format
362bfa
@@ -422,7 +423,7 @@ selections:
362bfa
 - var_auditd_action_mail_acct=root
362bfa
 - var_time_service_set_maxpoll=18_hours
362bfa
 - var_accounts_maximum_age_login_defs=60
362bfa
-- var_auditd_space_left=250MB
362bfa
+- var_auditd_space_left_percentage=25pc
362bfa
 - var_auditd_space_left_action=email
362bfa
 - var_auditd_disk_error_action=halt
362bfa
 - var_auditd_max_log_file_action=syslog
362bfa
diff --git a/tests/data/profile_stability/rhel8/stig_gui.profile b/tests/data/profile_stability/rhel8/stig_gui.profile
362bfa
index b5b60349a8..5b631a3fe0 100644
362bfa
--- a/tests/data/profile_stability/rhel8/stig_gui.profile
362bfa
+++ b/tests/data/profile_stability/rhel8/stig_gui.profile
362bfa
@@ -151,6 +151,7 @@ selections:
362bfa
 - auditd_data_retention_action_mail_acct
362bfa
 - auditd_data_retention_max_log_file_action
362bfa
 - auditd_data_retention_space_left_action
362bfa
+- auditd_data_retention_space_left_percentage
362bfa
 - auditd_local_events
362bfa
 - auditd_log_format
362bfa
 - auditd_name_format
362bfa
@@ -432,7 +433,7 @@ selections:
362bfa
 - var_auditd_action_mail_acct=root
362bfa
 - var_time_service_set_maxpoll=18_hours
362bfa
 - var_accounts_maximum_age_login_defs=60
362bfa
-- var_auditd_space_left=250MB
362bfa
+- var_auditd_space_left_percentage=25pc
362bfa
 - var_auditd_space_left_action=email
362bfa
 - var_auditd_disk_error_action=halt
362bfa
 - var_auditd_max_log_file_action=syslog