FireEye - Local logging level includes all errors and warnings

Information

Logs should include message levels of 'notice' and above. Higher levels such as 'crit' and 'err' do not include warnings of impending problems or notices of administrative actions.

Solution

The default level is 'notice'. Edit the configuration and add or modify this line:\n

logging local <none|emerg|alert|crit|err|warning|notice|info|debug>

Item Details

Audit Name: TNS FireEye

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: FireEye

Control ID: fe6b6dce52f558112cd73cde0c79765f66e82c65f07ba64cbae4226f938bd642