3.1000 - The system must send rsyslog output to a log aggregation server.

Information

Sending rsyslog output to another system ensures that the logs cannot be removed or modified in the event that the system is compromised or has a hardware failure.

Solution

Modify the "/etc/rsyslog.conf" file to contain a configuration line to send all "rsyslog" output to a log aggregation system:

*.* @@<log aggregation system name>

See Also

https://docs.fedoraproject.org/f28/system-administrators-guide/index.html

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-9(2)

Plugin: Unix

Control ID: 71c4de06e5312d3fe92e25459d14d693205c32ba73cb3567a90d7728c126769b