Rule ID
SV-240543r852585_rule
Version
V2R2
CCIs
Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Off-loading is a common process in information systems with limited audit storage capacity.
Check the "syslog" configuration file for remote syslog servers: # cat /etc/syslog-ng/syslog-ng.conf | grep logserver If no line is returned, or "logserver" is commented out, this is a finding.
Edit the syslog configuration file and add an appropriate remote syslog server:
In the /etc/syslog-ng/syslog-ng.conf file, the remote logging entries must be uncommented and the IP address must be modified to point to the remote syslog server:
#
# Enable this and adopt IP to send log messages to a log server.
#
destination logserver { udp("10.10.10.10" port(514)); };
log { source(src); destination(logserver); };