Information
This recommendation prevents the local syslogd daemon from accepting messages from other hosts on the network. Only central syslog servers, should accept remote syslog messages.
By default the syslogd daemon accepts all remote syslog messages as no authentication is required. This means that a hacker could flood a server with syslog messages and potentially fill up the /var filesystem.
Solution
If the server does not act as a central syslog server, suppress the logging of messages originating from remote servers:
# /usr/bin/chssys -s syslogd -a "-r"
Re-cycle syslogd to activate the configuration change:
# /usr/bin/stopsrc -s syslogd
# /usr/bin/startsrc -s syslogd