1.84 AZLX-23-002065

Information

Amazon Linux 2023 must authenticate the remote logging server for off-loading audit logs via rsyslog.

GROUP ID: V-274077RULE ID: SV-274077r1120219

Information stored in one location is vulnerable to accidental or incidental deletion or alteration.

Solution

Configure Amazon Linux 2023 to authenticate the remote logging server for off-loading audit logs by setting the following option in "/etc/rsyslog.conf" or "/etc/rsyslog.d/[customfile].conf":

$ActionSendStreamDriverAuthMode x509/name

See Also

https://workbench.cisecurity.org/benchmarks/26107