GEN005450 - The system must use a remote syslog server (loghost) - rsyslog.conf

Information

A syslog server (loghost) receives syslog messages from one or more systems. This data can be used as an authoritative log source in the event a system is compromised and its local logs are suspect.

Solution

Edit the syslog or rsyslog configuration file and add an appropriate remote syslog server.

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-3(2), CAT|II, CCE|CCE-4260-6, CCI|CCI-000136, Group-ID|V-22455, Rule-ID|SV-37811r2_rule, STIG-ID|GEN005450, Vuln-ID|V-22455

Plugin: Unix

Control ID: 9cb6cfea474edbf3708960130e23cfa2fbc96a3817bbfb8963f403e90b4296dc