OL 8 must use a separate file system for "/var/log".

STIG ID: OL08-00-010541  |  SRG: SRG-OS-000480-GPOS-00227 |  Severity: low |  CCI: CCI-000366 |  Vulnerability Id: V-248609 | 

Vulnerability Discussion

The use of separate file systems for different paths can protect the system from failures resulting from a file system becoming full or failing.

Check

Verify that a separate file system has been created for "/var/log".

Check that a file system has been created for "/var/log" with the following command:

$ sudo grep /var/log /etc/fstab

/dev/mapper/... /var/log xfs defaults,nodev,noexec,nosuid 0 0

If a separate entry for "/var/log" is not in use, this is a finding.

Fix

Migrate the "/var/log" path onto a separate file system.