8.2.1 Install the rsyslog package

Information

The rsyslog package is a third party package that provides many enhancements to syslog,
such as multi-threading, TCP communication, message filtering and data base support.

*Rationale*

The security enhancements of rsyslog such as connection-oriented (i.e. TCP) transmission
of logs, the option to log to database formats, and the encryption of log data en route to a
central logging server) justify installing and configuring the package.

Solution

Install the rsyslog package-# apt-get install rsyslog

See Also

https://workbench.cisecurity.org/files/91

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: Unix

Control ID: 1c0026e0bab306db08c8c49c0c6cdd46a888586292da23aaee335b46785cab51