6.1.3.1 Ensure rsyslog is installed

Information

The rsyslog software is recommended in environments where journald does not meet operation requirements.

The security enhancements of rsyslog such as connection-oriented (i.e. TCP) transmission of logs, the option to log to database formats, and the encryption of log data en route to a central logging server) justify installing and configuring the package.

Solution

Run the following command to install rsyslog :

# apt install rsyslog

See Also

https://workbench.cisecurity.org/benchmarks/18960

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-2, 800-53|AU-7, 800-53|AU-12, CSCv7|6.2, CSCv7|6.3

Plugin: Unix

Control ID: 7f9e8925c01db900f3baf5970729b5caa2f24a233a41e27b9da804f9921d2030