Information
A log file must already exist for rsyslog to be able to write to it.
*Rationale*
It is important to ensure that log files exist and have the correct permissions to ensure that
sensitive rsyslog data is archived and protected.
Solution
For sites that have not implemented a secure admin group-Create the /var/log/ directory and for each <logfile> listed in the /etc/rsyslog.conf or
/etc/rsyslog.d/* files, perform the following commands-
# touch <logfile>
# chown root-root <logfile>
# chmod og-rwx <logfile>For sites that have implemented a secure admin group-Create the /var/log/ directory and for each <logfile> listed in the /etc/rsyslog.conf file,
perform the following commands (where is the name of the security group)-# touch <logfile>
# chown root-<securegrp> <logfile>
# chmod g-wx,o-rwx<logfile>