OSX00155 - Enable remote logging

Information

In addition to local logging, consider using remote logging. Local logs can be altered if the computer is compromised.

Solution

1. Open a terminal session and enter the command- sudo pico /etc/syslog.conf
2. Add the following line to the top of the file, replacing your.log.server with the name or IP address of the log server, and keeping all other lines intact-
*.* @your.log.server
3. Exit, saving changes.
4. Reboot the system.

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx10.5_v1r2_stig_20110729.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-9(2), CAT|II, Rule-ID|SV-31339r1_rule, STIG-ID|OSX00155, Vuln-ID|V-25271

Plugin: Unix

Control ID: 19d840e0c8d4e8e04cdc05cf5af75a0db9780f8645db8a2d81056d821bbc71e4