4.2.2 Ensure rsyslog is installed

Information

The rsyslog software is recommended replacements to the original syslogd daemon which provide improvements over syslogd , such as connection-oriented (i.e. TCP) transmission of logs, the option to log to database formats, and the encryption of log data en route to a central logging server.

Rationale:

The security enhancements of rsyslog such as connection-oriented (i.e. TCP) transmission of logs, the option to log to database formats, and the encryption of log data en route to a central logging server) justify installing and configuring the package.

Solution

Install rsyslog using one of the following commands:

# yum install rsyslog

See Also

https://workbench.cisecurity.org/files/2449

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-3, 800-53|AU-12, CSCv6|2.2, CSCv7|6.2, CSCv7|6.3

Plugin: Unix

Control ID: 3a11201354e44e7c94d644de67331335c3d99b3d071efc5e5f2777c21080006a