2.2.4 Set IP address for 'logging host'

Information

Log system messages and debug output to a remote host.

Rationale:

Cisco routers can send their log messages to a Unix-style Syslog service. A syslog service simply accepts messages and stores them in files or prints them according to a simple configuration file. This form of logging is best because it can provide protected long-term storage for logs (the devices internal logging buffer has limited capacity to store events.) In addition, logging to an external system is highly recommended or required by most security standards. If desired or required by policy, law and/or regulation, enable a second syslog server for redundancy.

Impact:

Logging is an important process for an organization managing technology risk. The 'logging host' command sets the IP address of the logging host and enforces the logging process.

Solution

Designate one or more syslog servers by IP address.

hostname(config)#logging host {syslog_server}

Default Value:

System logging messages are not sent to any remote host.

See Also

https://workbench.cisecurity.org/files/3829

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-6(3), CSCv7|6.6, CSCv7|6.8

Plugin: Cisco

Control ID: 006d247e8290f9da894c69056a2114ce233ef921c6a21efb7d2ce64dfd808baf