8.2.4 Create and Set Permissions on rsyslog Log Files - permissions

Information

A log file must already exist for rsyslog to be able to write to it. It is important to ensure that log files exist and have the correct permissions to ensure that sensitive rsyslog data is archived and protected.

Solution

For sites that have not implemented a secure admin group- Create the /var/log/ directory and for each <logfile> listed in the /etc/rsyslog.conf or /etc/rsyslog.d/* files, perform the following commands- # touch <logfile> # chown root-root <logfile> # chmod og-rwx <logfile> For sites that have implemented a secure admin group- Create the /var/log/ directory and for each <logfile> listed in the /etc/rsyslog.conf file, perform the following commands (where is the name of the security group)- # touch <logfile> # chown root-<securegrp> <logfile> # chmod g-wx,o-rwx<logfile>

See Also

https://workbench.cisecurity.org/files/85

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-9(4)

Plugin: Unix

Control ID: 4ec83bfe50f774aa578a6bfa268fb0949fc06e359a2f603f57e6c3cdb1317816