5.1.1.6 Ensure rsyslog is not configured to receive logs from a remote client

Information

Syslog supports the ability to receive messages from remote hosts, thus acting as a log server. Clients should not receive data from other hosts.

If a client is configured to also receive data, thus turning it into a server, the client system is acting outside its operational boundary.

Solution

If the result does not include -s flag, then the following commands will fix this:

# sysrc syslogd_flags+=" -s"

See Also

https://workbench.cisecurity.org/benchmarks/19044

Item Details

Category: AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

References: 800-53|AU-2, 800-53|AU-7, 800-53|AU-12, 800-53|CM-6, 800-53|CM-7, CSCv7|6.2, CSCv7|6.3, CSCv7|9.2

Plugin: Unix

Control ID: 8036fe65b2efb5f67fbf6bd7cf9684d9ad8d0762692ada7b509ca7c3111ae04b