2.12 Configure centralized and remote logging

Information

https://docs.docker.com/engine/admin/logging/overview/

Solution

Step 1- Setup the desired log driver by following its documentation.
Step 2- Start the docker daemon with that logging driver.
For example,
docker run --log-driver=syslog --log-opt syslog-address=tcp-//192.xxx.xxx.xxx

Impact-
None.
Default Value-
By default, container logs are maintained as json files

See Also

https://workbench.cisecurity.org/files/516

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-9(2)

Plugin: Unix

Control ID: a0820c6acbcd04e4e46afa5744332a92cbfec1c4a2b177778358bf30a947e872