OL07-00-031000 - The Oracle Linux operating system must send rsyslog output to a log aggregation server.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Sending rsyslog output to another system ensures that the logs cannot be removed or modified in the event that the system is compromised or has a hardware failure.

Solution

Modify the '/etc/rsyslog.conf' or an '/etc/rsyslog.d/*.conf' file to contain a configuration line to send all 'rsyslog' output to a log aggregation system:
*.* @@<log aggregation system name>

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_7_V2R11_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000366, Rule-ID|SV-221835r603260_rule, STIG-ID|OL07-00-031000, STIG-Legacy|SV-108513, STIG-Legacy|V-99409, Vuln-ID|V-221835

Plugin: Unix

Control ID: 6535294d39187d039ba511f049de091ade92d66e2724dcdd1b817b8f36371281