5.1.2 Create and Set Permissions on syslog Log Files - /var/log/kern.log

Information

A log file must already exist for syslog to be able to write to it.

Rationale:

It is important to ensure that log files exist and have the correct permissions to ensure that sensitive syslog data is archived and protected.

Solution

For sites that have not implemented a secure admin group: For each LOGFILE listed in the /etc/syslog.conf file, perform the following commands:

# touch <LOGFILE>
# chown root:root <LOGFILE>
# chmod og-rwx <LOGFILE>

For sites that have implemented a secure admin group: For each LOGFILE listed in the /etc/syslog.conf file, perform the following commands (where is the name of the security group):

# touch <LOGFILE>
# chown root:<securegrp> <LOGFILE>
# chmod g-wx,o-rwx <LOGFILE>

Default Value:

OS Default: N/A

See Also

https://workbench.cisecurity.org/files/3096