FireEye - Remote syslog is enabled

Information

Security log information could be modified or lost if the host is compromised or fails. Syslog messages should be sent to a remote host.

Solution

The default level is 'notice'. Edit the configuration and add or modify this line:\n

logging <syslog_server_IP>

Item Details

Audit Name: TNS FireEye

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: FireEye

Control ID: f4e06fdffdd400932d23efd903d8ce10e8d0af33d992ee5f3a6831c911048e42