Rule ID
SV-285237r1258948_rule
Version
V1R1
Protection of log data includes ensuring log data is not accidentally lost or deleted. Backing up audit records to a different system or onto separate media than the system being audited on a defined frequency helps to ensure the audit records will be retained in the event of a catastrophic system failure. This also helps to ensure a compromise of the information system being audited does not result in a compromise of the audit records. This requirement only applies to applications that have a native backup capability for audit records. Operating system backup requirements cover applications that do not provide native backup functions. Satisfies: SRG-APP-000125-DNS-000012, SRG-APP-000226-DNS-000032
Verify Infoblox external logging is operational and that messages from the audit log are also forwarded to the remote log system. 1. Navigate to Infoblox Grid >> Grid Manager >> Grid Properties (Toolbar menu), or to System >> System Manager >> System Properties if using a standalone configuration. 2. Select the "Monitoring" tab. 3. Validate that the checkbox for "Log to External Syslog Servers" is selected and an External Syslog Server is configured. 4. Validate that the "Copy Audit Log Message to Syslog" checkbox is selected. 5. When complete, click "Cancel" to exit the "Properties" screen. If both "Log to External Syslog Servers" and "Copy Audit Log Message to Syslog" are not configured, this is a finding.
Configure an External Syslog Server and Audit Log backups: 1. From the Infoblox GUI, navigate to Infoblox Grid >> Grid Manager >> Grid Properties (Toolbar menu) >> Monitoring tab. 2. Select the checkbox for "Log to External Syslog Servers". 3. Select the (+) icon to add an External Syslog Server. 4. Enter the IP Address, Transport Protocol (UDP/TCP), Interface, Node ID, Source, Severity and Port Number of the External Syslog Server. Note: If using Secure TCP, the Server Certificate will be an additional (required) field. 5. Select "Add". 6. Check the "Copy Audit Log Message to Syslog" checkbox. 7. Select "Save & Close".