1.1.7 Logging

Information

Logging is a critical part of network security. Maintaining an audit trail of system activity logs (syslog) can help identify configuration errors, understand past intrusions, troubleshoot service disruptions, and react to probes and scans of the network.

Syslog levels 0-6 are the levels required to collect the necessary information to help in the recovery process. It is recommended to log all messages except debugging and send all log data to a syslog server.

Solution

Configure a destination for syslog messages. Logging should be sent over the management vrf.

switch(config)# logging trap 6
switch(config)# logging {vrf [management vrf]} host {ip address}

See Also

https://workbench.cisecurity.org/benchmarks/25683

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: Arista

Control ID: 3158ba17d323c64cb775c38f9c315348e0f9e11010ec07ef95bd26261a6e026f