FireEye - Local logging level is not overridden except by defaults

Information

Logs should include message levels of 'notice' and above. By default two event classes are overridden with a priority of 'notice'. If additional overrides are found logs may not contain all expected events.

Solution

If other overrides are present remove them by editing the configuration and entering 'no' before the override to be removed.

Item Details

Audit Name: TNS FireEye

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: FireEye

Control ID: 64005f38662510401dbcf56ce40c25e7902a5a2a7697edeb91bb13547e11cc94