STIGQter STIGQter: STIG Summary: Central Log Server Security Requirements Guide Version: 3 Release: 4 Benchmark Date: 01 Apr 2026:

For devices and hosts within the scope of coverage, the Central Log Server must be configured to automatically aggregate events that indicate account actions.

DISA Rule

SV-206516r961863_rule

Vulnerability Number

V-206516

Group Title

SRG-APP-000516

Rule Version

SRG-APP-000516-AU-000370

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Central Log Server to automatically aggregate events that indicate account actions for each device and host within its scope of coverage.

Check Contents

Examine the configuration.

Verify the Central Log Server automatically aggregates events that indicate account actions for each device and host within its scope of coverage.

If the Central Log Server is not configured to automatically aggregate events that indicate account actions for each device and host within its scope of coverage, this is a finding.

Vulnerability Number

V-206516

Documentable

False

Rule Version

SRG-APP-000516-AU-000370

Severity Override Guidance

Examine the configuration.

Verify the Central Log Server automatically aggregates events that indicate account actions for each device and host within its scope of coverage.

If the Central Log Server is not configured to automatically aggregate events that indicate account actions for each device and host within its scope of coverage, this is a finding.

Check Content Reference

M

Target Key

2901