1.10.4 Ensure 'syslog hosts' is configured correctly

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Sets the SNMP notification recipient or the NMS or SNMP manager that can connect to the ASA.

Rationale:

Syslog messages are an invaluable tool for accounting, monitoring, and routine troubleshooting. Logging to a central syslog server is a method of collecting messages from devices to a server running a syslog daemon. This helps in aggregation of logs and alerts. This form of logging provides protected long-term storage for logs, since are also useful in incident handling.

Solution

Run the following to configure the Syslog server

HOSTNAME(CONFIG)# LOGGING HOST _<interface_name> <host_ip_address>_

See Also

https://benchmarks.cisecurity.org/tools2/cisco/CIS_Cisco_Firewall_Benchmark_v4.0.0.pdf

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-9

Plugin: Cisco

Control ID: 240a12d4857ed9d5dae0c0c93005efd4eb8894a8f203949e33c46866b7bcb0bb