8.2.5 Configure rsyslog to Send Logs to a Remote Log Host

Information

NOTE: Update SYSLOG_SERVER with the appropriate value for the local environment.

Solution

Edit the /etc/rsyslog.conf file and add the following line (where logfile.example.com is the
name of your central log host).
*.* @@loghost.example.com
# Execute the following command to restart rsyslogd
# pkill -HUP rsyslogdNote- The double 'at' sign (@@) directs rsyslog to use TCP to send log messages to the
server, which is a more reliable transport mechanism than the default UDP protocol.

See Also

https://workbench.cisecurity.org/files/91

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-9(2)

Plugin: Unix

Control ID: 8ea254983bbd11e1238dd3f5806a58e844050765db9a7df829787f1cbf434d3e