8.3.1 Centralized Logging and Reporting

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Device logs should be sent to a centralized device for log collection, retention, and reporting. This could be a SIEM. syslog device, FortiAnalyzer, FortiManager, etc.

Rationale:

Centralized logging allows for more reliable log retention and more enriched log data for review and reporting.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure a remote server for logs to be sent to.

Access the FortiGate administrative web access page and to to Log & Report > Log Settings and under 'Remote Logging and Archiving' configure a remote server to send logs to.

See Also

https://workbench.cisecurity.org/files/4077

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12

Plugin: FortiGate

Control ID: 6176a5e3ba931a2530596870092cdada40993b548f1fac8a18ba771ddc16cba6