4.2.3 Ensure rsyslog or syslog-ng is installed

Information

The rsyslog and syslog-ng software are recommended replacements to the original syslogd daemon which provide improvements over syslogd, such as connection-oriented (i.e. TCP) transmission of logs, the option to log to database formats, and the encryption of log data en route to a central logging server. The security enhancements of rsyslog and syslog-ng such as connection-oriented (i.e. TCP) transmission of logs, the option to log to database formats, and the encryption of log data en route to a central logging server) justify installing and configuring the package.

NOTE: Nessus has not identified that rsyslog or syslog-ng is installed.

Solution

Install rsyslog or syslog-ng using one of the following commands: # apt-get install rsyslog# apt-get install syslog-ng

See Also

https://workbench.cisecurity.org/files/1866

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-2, CSCv6|6.2

Plugin: Unix

Control ID: 53a67790787d9c04c4eb14df98c137ecf7d3409ba1cf01a8e853d9ae48918d3b