4.2.1.1 Ensure rsyslog is installed

Information

The rsyslog software is a recommended replacement to the original syslogd daemon.

rsyslog provides improvements over syslogd, including:

connection-oriented (i.e. TCP) transmission of logs

The option to log to database formats

Encryption of log data en route to a central logging server

Rationale:

The security enhancements of rsyslog such as connection-oriented (i.e. TCP) transmission of logs, the option to log to database formats, and the encryption of log data en route to a central logging server) justify installing and configuring the package.

Solution

Run the following command to install rsyslog:

# yum install rsyslog

See Also

https://workbench.cisecurity.org/files/2851

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(5)

Plugin: Unix

Control ID: 44aaf7e8719291f68a8a7365b0e9b5dca551e040a140c5ef3693a45b856e6688