Information
A log file must already exist for syslog to be able to write to it.
Rationale:
It is important to ensure that log files exist and have the correct permissions to ensure that sensitive syslog data is archived and protected.
Solution
For sites that have not implemented a secure admin group: For each LOGFILE listed in the /etc/syslog.conf file, perform the following commands:
# touch <LOGFILE>
# chown root:root <LOGFILE>
# chmod og-rwx <LOGFILE>
For sites that have implemented a secure admin group: For each LOGFILE listed in the /etc/syslog.conf file, perform the following commands (where is the name of the security group):
# touch <LOGFILE>
# chown root:<securegrp> <LOGFILE>
# chmod g-wx,o-rwx <LOGFILE>
Default Value:
OS Default: N/A