4.2.2.4 Ensure syslog-ng is configured to send logs to a remote log host - destination logserver

Information

The syslog-ng utility supports the ability to send logs it gathers to a remote log host or to receive messages from remote hosts, reducing administrative overhead.

NOTE - Nessus has not performed this check. syslog-ng does not seem to be installed and this check is not applicable.

Solution

Edit the /etc/syslog-ng/syslog-ng.conf file and add the following lines (where logfile.example.com is the name of your central log host).
destination logserver { tcp("logfile.example.com" port(514)); };
log { source(src); destination(logserver); };

Run the following command to reload the syslog-ng configuration: # pkill -HUP syslog-ng

See Also

https://workbench.cisecurity.org/files/1863

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-9(2), CSCv6|6.6

Plugin: Unix

Control ID: f06bb9179c63fc69f009038df848e0ae7e86daab5fe848e8856572a96bf9b1cf