5.4 Ensure that new entries are appended to the end of the log file

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

By default, new log entries will overwrite old entries after a restart of the mongod or Mongols service. Enabling the systemLog.logAppend setting causes new entries to be appended to the end of the log file rather than overwriting the existing content of the log when the mongos or mongod instance restarts.

Rationale:

Allowing old entries to be overwritten by new entries instead of appending new entries to the end of the log may destroy old log data that is needed for a variety of purposes.

Solution

Set

'systemLog:
logAppend: true'

to true in the /etc/mongod.conf file.

See Also

https://workbench.cisecurity.org/benchmarks/15135