SRG-OS-000215-ESXI5 - The operating system must back up audit records on an organization-defined frequency onto a different system or media than the system being audited.

Information

Remote logging to a central log host provides a secure, centralized store for ESXi logs. By gathering host log files onto a central host it can more easily monitor all hosts with a single tool. It can also do aggregate analysis and searching to look for such things as coordinated attacks on multiple hosts. Logging to a secure, centralized log server also helps prevent log tampering and also provides a long-term audit record.

Solution

Step 1: Verify the vSphere Syslog Collector syslog host has been configured. If not, install/enable the vSphere Syslog Collector.
Step 2: From the vSphere Client: Select the host and click 'Configuration >> Advanced Settings >> Syslog >> Global'.
Step 3: Set 'Syslog.global.logHost' to the syslog server hostname.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_ESXi5_Server_V2R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Group-ID|V-39409, Rule-ID|SV-250646r798937_rule, STIG-ID|SRG-OS-000215-ESXI5, STIG-Legacy|SV-51267, STIG-Legacy|V-39409, Vuln-ID|V-250646

Plugin: VMware

Control ID: 262a4174267c1f2518913aa23b411bd66470ae9ed3d95ce7aa727d5b3e5ec3f8