7.3 Ensure className is set correctly in context.xml

Information

Ensure the className attribute is set to AccessLogValve. The className attribute determines the access log valve to be used for logging.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Add the following statement into the $CATALINA_BASEwebapps<app name>METAINFcontext.xml file if it does not already exist.
<Valve className="org.apache.catalina.valves.AccessLogValve" directory="$CATALINA_HOME/logs/" prefix="access_log" fileDateFormat="yyyy-MM-dd.HH" suffix=".log" pattern="%t %H cookie:%{SESSIONID}c request:%{SESSIONID}r %m %U %s %q %r" />

See Also

https://workbench.cisecurity.org/files/266

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12

Plugin: Unix

Control ID: e6430100d50e9fd2a9f7bb743b59500376995cb67929546110e19ab0a322c696