1.10.8 Ensure 'syslog logging facility' is equal to '23'

Information

Sets the facility (location) on the syslog server for the log messages sent by the security appliance

Rationale:

Logs should be directed to a consistent and expected logging facility to ensure proper processing and storage by the remote system. There are eight possible logging facilities: 16 (LOCAL0) through 23 (LOCAL7) for the logs messages sent by the security appliance to the syslog server.

Solution

Step 1: Run the following command to set the logging facility to 23

hostname(config)# logging facility 23

Default Value:

The default logging facility value is 20

Additional Information:

http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/general/asa_91_general_config/monitor_syslog.html

See Also

https://workbench.cisecurity.org/files/3246

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4

Plugin: Cisco

Control ID: 480795fbac0988df09faa8412dc11e514d6e513d53af1faa11dd00de72a860e1