5.4 Ensure that new entries are appended to the end of the log file

Information

By default, new log entries will overwrite old entries after a restart of the mongod or Mongols service. Enabling the systemLog.logAppend setting causes new entries to be appended to the end of the log file rather than overwriting the existing content of the log when the mongos or mongod instance restarts.

Rationale:

Allowing old entries to be overwritten by new entries instead of appending new entries to the end of the log may destroy old log data that is needed for a variety of purposes.

Solution

Set systemLog.logAppend to true in the /etc/mongod.conf file.

See Also

https://workbench.cisecurity.org/files/168

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: Unix

Control ID: f741b7600263cf40b088a012b6752216841083d9faa6801c4f0efa25e42f59fc