4.2.1.4 Ensure rsyslog is configured to send logs to a remote log host

Information

The rsyslog utility supports the ability to send logs it gathers to a remote log host running syslogd(8) or to receive messages from remote hosts, reducing administrative overhead.

Solution

Edit the /etc/rsyslog.conf and /etc/rsyslog.d/*.conf files and add the following line (where loghost.example.com is the name of your central log host):
*.* @@loghost.example.com

Run the following command to reload the rsyslogd configuration:
# pkill -HUP rsyslogd

See Also

https://workbench.cisecurity.org/files/1856

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-9, CSCv6|6.6

Plugin: Unix

Control ID: 09e1b0f3fe1d0824962e03628049952e4f09f4122ccc21e448c8a066ac9d79d7