FireEye - Remote syslog logging level includes all errors and warnings

Information

Syslog messages sent to a remote host should include message levels of 'notice' and above. Higher levels such as 'crit' and 'err' do not include warnings of impending problems or notices of administrative actions.

Solution

Check organizational standards to determine the appropriate level for this appliance. Edit the configuration and add or modify this line:\n

logging <syslog_server_IP> trap <none|emerg|alert|crit|err|warning|notice|info|debug>\n

Omit the trap parameter to use the default level, 'notice'.

Item Details

Audit Name: TNS FireEye

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-9(2)

Plugin: FireEye

Control ID: 9715f3210551c3ed648666dada51b7eb355a8722030f06da649d4c12398de784