GEN005420 - The /etc/syslog.conf file must be group-owned by bin, sys, or system.

Information

If the group owner of /etc/syslog.conf is not root, bin, or sys, unauthorized users could be permitted to view, edit, or delete important system messages handled by the syslog facility.

Solution

Change the group owner of the /etc/syslog.conf file to bin, sys, or system.
Procedure:
# chgrp system /etc/syslog.conf

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip