4.2.1.5 Ensure journald is not configured to send logs to rsyslog

Information

Data from journald should be kept in the confines of the service and not forwarded on to other services.

Rationale:

IF journald is the method for capturing logs, all logs of the system should be handled by journald and not forwarded to other logging mechanisms.

NOTE: Nessus has determined that this check is not applicable to the target device as it is currently configured. Please review the benchmark to ensure target compliance.

Solution

Edit the /etc/systemd/journald.conf file and files in /etc/systemd/journald.conf.d/ and ensure that ForwardToSyslog=yes is removed.
Restart the service:

# systemctl restart systemd-journald

See Also

https://workbench.cisecurity.org/files/4115