5.1.2.1.4 Ensure journald is not configured to receive logs from a remote client

Information

Journald supports the ability to receive messages from remote hosts, thus acting as a log server. Clients should not receive data from other hosts.

NOTE:

- The same package, systemd-journal-remote is used for both sending logs to remote hosts and receiving incoming logs.
- With regards to receiving logs, there are two services; systemd-journal-remote.socket and systemd-journal-remote.service

If a client is configured to also receive data, thus turning it into a server, the client system is acting outside it's operational boundary.

Solution

Run the following command to disable systemd-journal-remote.socket :

# systemctl --now mask systemd-journal-remote.socket

See Also

https://workbench.cisecurity.org/benchmarks/15963

Item Details

Category: AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

References: 800-53|AU-2, 800-53|AU-7, 800-53|AU-12, 800-53|CM-6, 800-53|CM-7, CSCv7|6.2, CSCv7|6.3, CSCv7|9.2

Plugin: Unix

Control ID: e3c50ae35d84c427679d65208b2b885f33b51b53b19da3aff7259fc8866f9520