4.2.1.4 Ensure rsyslog is configured to send logs to a remote log host

Information

The rsyslog utility supports the ability to send logs it gathers to a remote log host running syslogd(8) or to receive messages from remote hosts, reducing administrative overhead.

Solution

Edit the /etc/rsyslog.conf and /etc/rsyslog.d/*.conf files and add the following line (where loghost.example.com is the name of your central log host):
*.* @@loghost.example.com

Run the following command to reload the rsyslogd configuration:
# pkill -HUP rsyslogd

See Also

https://workbench.cisecurity.org/files/1856

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-9, CSCv6|6.6

Plugin: Unix

Control ID: 26cc72c8f16feb75d0f9e2e76378faa07f346320ea6f4e9cda176dfbfb3bf787