2.12 Configure centralized and remote logging

Information

https://docs.docker.com/engine/admin/logging/overview/

Solution

Step 1- Setup the desired log driver by following its documentation.Step 2- Start the docker daemon with that logging driver.For example,dockerd --log-driver=syslog --log-opt syslog-address=tcp-//192.xxx.xxx.xxxImpact-None.Default Value-By default, container logs are maintained as json files

See Also

https://workbench.cisecurity.org/files/517

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-9(2)

Plugin: Unix

Control ID: 0f542b5903082ac2fa0cd69edd100d792de7c50b66e81469ab59c8ccdb1551d3