RHEL-06-000134 - All rsyslog-generated log files must be group-owned by root.

Information

The log files generated by rsyslog contain valuable information regarding system configuration, user authentication, and other such information. Log files should be protected from unauthorized access.

Solution

The group-owner of all log files written by 'rsyslog' should be root. These log files are determined by the second part of each Rule line in '/etc/rsyslog.conf' and typically all appear in '/var/log'. For each log file [LOGFILE] referenced in '/etc/rsyslog.conf', run the following command to inspect the file's group owner:

$ ls -l [LOGFILE]

If the owner is not 'root', run the following command to correct this:

# chgrp root [LOGFILE]

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_6_V2R2_STIG.zip

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-11b., CAT|II, CCI|CCI-001314, Rule-ID|SV-217939r603264_rule, STIG-ID|RHEL-06-000134, STIG-Legacy|SV-50320, STIG-Legacy|V-38519, Vuln-ID|V-217939

Plugin: Unix

Control ID: a2c7a234869bcbb63f23fd148a7a2c65b0a6319061940ca5fff9ed718275271c