OSX00155 M6 - Remote logging must be enabled

Information

In addition to local logging, remote logging must also be enabled. Local logs can be altered if the computer is compromised. Remote logging mitigates the risk of having the logs altered.

Solution

Open a terminal session and enter the following command.

sudo pico /etc/syslog.conf

Add the following line to the top of the file, replacing 'your.log.server' with the name or IP address of the log server, and keeping all other lines intact.
*.* @your.log.server
Exit, saving changes.
Reboot the system.

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx_10.6_v1r3_stig_20130426.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-9(2), CAT|II, Rule-ID|SV-38523r1_rule, STIG-ID|OSX00155-M6, Vuln-ID|V-25271

Plugin: Unix

Control ID: 810343f88dd980823def650617e6161503250d92d91d1a8d370c9a76802137e1