BSI-100-2: S 4.106: Activation of system logging: /etc/rsyslog.conf - local0,local1.info

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

All changes made to /etc/syslog.conf must be documented. When making modifications to the existing IT system, at first everything should be logged. After that, individual areas can be deactivated in stages as required. The /var partition must be sufficiently large to accommodate the log files.

* Please note that the equivalent file on a Red Hat system is /etc/rsyslog.conf

Safeguard Catalogues: S 4: Hardware and software

S 4.106: Activation of system logging

See Also

https://www.bsi.bund.de/cae/servlet/contentblob/471430/publicationFile/28223/standard_100-2_e_pdf.pdf

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12

Plugin: Unix

Control ID: c03fd6708cb8b33967b55a4d331a691df9f41b2eb8fe622c2b4b7763e158f34e