5.2.3 Configure /etc/rsyslog.conf 'daemon /var/log/daemon.log'

Information

Configuration Level : Level-I

Solution

Edit the following lines in the /etc/rsyslog.conf file as appropriate for your environment-auth,user.* /var/log/messages kern.* /var/log/kern.log daemon.* /var/log/daemon.log syslog.* /var/log/syslog lpr,news,uucp,local0,local1,local2,local3,local4,local5,local6.* /var/log/unused.log # Execute the following command to restart rsyslogd # pkill -HUP rsyslogd

See Also

https://workbench.cisecurity.org/files/214

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12

Plugin: Unix

Control ID: dea2fbdc42e49a820ffe87eb585f1822ae3947648504bcea42cd4b8fa3687586