4.2.1.1 Ensure rsyslog is installed

Information

The rsyslog software is a recommended replacement to the original syslogd daemon
which provide improvements over syslogd, such as connection-oriented (i.e. TCP)
transmission of logs, the option to log to database formats, and the encryption of log data
en route to a central logging server.

Rationale:

The security enhancements of rsyslog such as connection-oriented (i.e. TCP) transmission
of logs, the option to log to database formats, and the encryption of log data en route to a
central logging server) justify installing and configuring the package.

Solution

Install rsyslog or using the appropriate package manager or manual installation:

# yum install rsyslog

# apt-get install rsyslog

# zypper install rsyslog

See Also

https://workbench.cisecurity.org/files/2420