5.2.4 Create and Set Permissions on rsyslog Log Files - /var/log/kern.log

Information

A log file must already exist for rsyslog to be able to write to it.

Rationale:

It is important to ensure that log files exist and have the correct permissions to ensure that sensitive rsyslog data is archived and protected.

Solution

For sites that have not implemented a secure admin group:
Create the /var/log/ directory and for each listed in the /etc/rsyslog.conf file, perform the following commands:

# touch <logfile>
# chown root:root <logfile>
# chmod og-rwx <logfile>

For sites that have implemented a secure admin group:
Create the /var/log/ directory and for each listed in the /etc/rsyslog.conf file, perform the following commands (where is the name of the security group):

# touch <logfile>
# chown root:<securegrp> <logfile>
# chmod g-wx,o-rwx <logfile>

Default Value:

OS Default: No

See Also

https://workbench.cisecurity.org/files/3096

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12, CSCv6|3.1, CSCv7|6.3

Plugin: Unix

Control ID: e648d349e4501ca6fa31e85569bb5e32b38fcba0c66e219f3b00cfa8f487dc22