1.1.1.3.4 Set 'Maximum system log size' to '16384'

Information

This policy setting specifies the maximum size of the System event log. In Windows Vista and Windows Server 2008 this setting has been replaced by another called System, located at

Computer Configuration\Administrative Templates\Windows Components\Event Log Service. If both this setting and the new one are configured the settingat

Computer Configuration\Administrative Templates\Windows Components\Event Log Service will take precedence. If events are not recorded it may be difficult or impossible to determine the root cause of system problems or the unauthorized activities of malicious users

Solution

To implement the recommended configuration state, set the following Group Policy setting to 16384.

Computer Configuration\Windows Settings\Security Settings\Event Log\Maximum system log size

Impact- When event logs fill to capacity, they will stop recording information unless the retention method for each is set so that the computer will overwrite the oldest entries with the most recent ones. To mitigate the risk of loss of recent data, you can configure the retention method so that older events are overwritten as needed. The consequence of this configuration is that older events will be removed from the logs. Attackers can take advantage of such a configuration, because they can generate a large number of extraneous events to overwrite any evidence of their attack. These risks can be somewhat reduced if you automate the archival and backup of event log data. Ideally, all specifically monitored events should be sent to a server that uses Microsoft Operations Manager (MOM) or some other automated monitoring tool. Such a configuration is particularly important because an attacker who successfully compromises a server could clear the Security log. If all events are sent to a monitoring server, then you will be able to gather forensic information about the attacker's activities.

See Also

https://workbench.cisecurity.org/files/42

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4, CCE|CCE-3506-3, CSCv6|6.3

Plugin: Windows

Control ID: af32d88dfe2760889aa312dad36a6693a55c0100b2d6be69b64576a4b5ceb0aa