4.2.2.4 Ensure syslog-ng is configured to send logs to a remote log host - log src

Information

The syslog-ng utility supports the ability to send logs it gathers to a remote log host or to receive messages from remote hosts, reducing administrative overhead.

Solution

Edit the /etc/syslog-ng/syslog-ng.conf file and add the following lines (where logfile.example.com is the name of your central log host).
destination logserver { tcp("logfile.example.com" port(514)); };
log { source(src); destination(logserver); };

Run the following command to reload the syslog-ng configuration: # pkill -HUP syslog-ng

See Also

https://workbench.cisecurity.org/files/1856

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12, CSCv6|6.6

Plugin: Unix

Control ID: 8b882cdd0cf2e5140a98396ab7bff005db6d66032905d852f3d9b5b5b1075a99