SV-234177r961833_rule
V-234177
SRG-APP-000506-NDM-000323
FGFW-ND-000090
CAT II
10
When Event Logging is enabled, the device will audit concurrent logons from different workstations. To enable event logging, log in to the FortiGate GUI with Super-Admin privilege.
1. Open a CLI console, via SSH or available from the GUI.
2. Run the following command:
# config log eventfilter
# set event enable
# set system enable
# end
Log in to the FortiGate GUI with Super-Admin privilege.
1. Open a CLI console, via SSH or available from the GUI.
2. Run the following command:
# show full-configuration log eventfilter | grep -i 'event\|system'
The output should be:
set event enable
set system enable
If the event and system parameters are set to disable, this is a finding.
V-234177
False
FGFW-ND-000090
Log in to the FortiGate GUI with Super-Admin privilege.
1. Open a CLI console, via SSH or available from the GUI.
2. Run the following command:
# show full-configuration log eventfilter | grep -i 'event\|system'
The output should be:
set event enable
set system enable
If the event and system parameters are set to disable, this is a finding.
M
5260