6.1.3.7 Ensure rsyslog is not configured to receive logs from a remote client

Information

rsyslog supports the ability to receive messages from remote hosts, thus acting as a log server. Clients should not receive data from other hosts.

If a client is configured to also receive data, thus turning it into a server, the client system is acting outside its operational boundary.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

NOTE: journald or rsyslog was not found to be active. Review benchmark guidance to ensure local compliance.

Solution

Unless the system's primary function is to serve as a logfile server , modify the files returned by the Audit Procedure and remove the specific lines highlighted by the audit. Verify none of the following entries are present in the rsyslog configuration.

advanced format

module(load="imtcp")
input(type="imtcp" port="514")

deprecated legacy format

$ModLoad imtcp
$InputTCPServerRun

Reload the service:

# systemctl reload-or-restart rsyslog

See Also

https://workbench.cisecurity.org/benchmarks/18959

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 6e140f73fcf1923dd6ac0b115b7d77bd4e4f51276ecafd1565052a4263956bf1