STIGQter STIGQter: STIG Summary: Ivanti Sentry 9.x NDM Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

Sentry must be configured to send log data to a central log server for the purpose of forwarding alerts to the administrators and the ISSO.

DISA Rule

SV-251006r1028244_rule

Vulnerability Number

V-251006

Group Title

SRG-APP-000516-NDM-000350

Rule Version

MOIS-ND-000980

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the Sentry to forward syslog data using the steps below Refer to "Sentry Guide for Core", section "Syslog", page 140.

1. Log in to the Sentry.
2. Navigate to "Settings".
3. Scroll down to "Syslog".
4. If there is no syslog server entry, ADD the server:
a. Add Server IP address.
b. Add Port.
c. Select/add Facility Types and Log Levels.
d. Enable Admin state.

Check Contents

To identify/validate Sentry support for syslog forwarding, follow the navigation steps below.

1. Log in to the Sentry.
2. Navigate to "Settings".
3. Scroll down to "Syslog".
4. Verify that a syslog server has been configured correctly.
a. Verify Server IP address.
b. Verify Port.
c. Verify Facility Types.
d. Verify Admin state is enabled.

If syslog forwarding has not been implemented, this is a finding.

Vulnerability Number

V-251006

Documentable

False

Rule Version

MOIS-ND-000980

Severity Override Guidance

To identify/validate Sentry support for syslog forwarding, follow the navigation steps below.

1. Log in to the Sentry.
2. Navigate to "Settings".
3. Scroll down to "Syslog".
4. Verify that a syslog server has been configured correctly.
a. Verify Server IP address.
b. Verify Port.
c. Verify Facility Types.
d. Verify Admin state is enabled.

If syslog forwarding has not been implemented, this is a finding.

Check Content Reference

M

Target Key

5438