5.1.1.3 Ensure journald is configured to send logs to rsyslog

Information

Data from systemd-journald may be stored in volatile memory or persisted locally on the server. Utilities exist to accept remote export of systemd-journald logs, however, use of the rsyslog service provides a consistent means of log collection and export.

-IF- rsyslog is the preferred method for capturing logs, all logs of the system should be sent to it for further processing.

Note: This recommendation only applies if rsyslog is the chosen method for client side logging. Do not apply this recommendation if systemd-journald is used.

Solution

Create or edit the file /etc/systemd/journald.conf and add or edit the following line:

ForwardToSyslog=yes

Reload the systemd-journald service:

# systemctl systemctl reload-or-try-restart systemd-journald.service

See Also

https://workbench.cisecurity.org/benchmarks/15965

Item Details

Category: ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AC-3, 800-53|AU-2, 800-53|AU-4, 800-53|AU-6(3), 800-53|AU-7, 800-53|AU-12, 800-53|MP-2, 800-53|SI-5, CSCv7|6.2, CSCv7|6.3, CSCv7|6.5

Plugin: Unix

Control ID: 52f785d3c3f8b3f1491ef1eeb6d3b9bc78a665edfa461605d84b73222c8ff22d