29 - Configure a File Channel

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

To capture logs to a local file, setup a channel for the file. You may want to consider one log file for security related logs, and a second one with a dynamic severity level to be used as needed for debugging.

Rationale:

Logging security related events allows you to see what is affecting the server and adjust the server to prevent attacks.

Solution

In named.conf, configure a channel for a local security log file with the categories config, dnssec, network, security, updates, xfer-in and xfer-out. The local log file will be within the chroot directory.

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12

Plugin: Unix

Control ID: aabb24406b692100bef68b6cf68f55a5ef9b38b7782eca73ca48cdd5dbdff98d