5.3 Capture FTP and inetd Connection Tracing Info - Check if 'daemon.debug' is set to /var/log/connlog

Information

If the FTP service is enabled on the system, Item 5.2 enables the 'debugging' (-d) and connection logging (-l) flags to track FTP activity on the system. Similarly, the tracing (-t) option to inetd was enabled in Item 5.1 above. All of this information is logged to syslog, but the syslog daemon must be configured to capture this information to a file. The connlog file should be reviewed and archived on a regular basis.

See Also

https://workbench.cisecurity.org/files/633