10.15 Do not resolve hosts on logging valves

Information

Setting enableLookups to true on Connector will result in a DNS look-ups to obtain the host name of the remote client before logging any information. This uses additional resources when logging.

Allowing enableLookups adds additional overhead to resolve the host name of a remote client which is rarely needed.

Solution

In Connector elements, set the enableLookups attribute to false or remove it.

<Connector ... enableLookups="false" />

See Also

https://workbench.cisecurity.org/benchmarks/15137

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-8, CSCv7|7.7

Plugin: Unix

Control ID: d56448b3d5ea9795d19f89cc28f49f74ad230b0c81209953eb1d96e9c07cc353