STIGQter STIGQter: STIG Summary: Tri-Lab Operating System Stack (TOSS) 4 Security Technical Implementation Guide Version: 2 Release: 6 Benchmark Date: 01 Jul 2026:

Cron logging must be implemented in TOSS.

DISA Rule

SV-253101r991589_rule

Vulnerability Number

V-253101

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

TOSS-04-040590

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure "rsyslog" to log all cron messages by adding or updating the following line to "/etc/rsyslog.conf" or a configuration file in the /etc/rsyslog.d/ directory:

cron.* /var/log/cron

The rsyslog daemon must be restarted for the changes to take effect:
$ sudo systemctl restart rsyslog.service

Check Contents

Verify that "rsyslog" is configured to log cron events with the following command:

Note: If another logging package is used, substitute the utility configuration file for "/etc/rsyslog.conf" or "/etc/rsyslog.d/*.conf" files.

$ sudo grep -r cron /etc/rsyslog.conf /etc/rsyslog.d

/etc/rsyslog.conf:*.info;mail.none;authpriv.none;cron.none /var/log/messages
/etc/rsyslog.conf:# Log cron stuff
/etc/rsyslog.conf:cron.* /var/log/cron

If the command does not return a response, check for cron logging all facilities with the following command.

$ sudo grep -r /var/log/messages /etc/rsyslog.conf /etc/rsyslog.d

/etc/rsyslog.conf:*.info;mail.none;authpriv.none;cron.none /var/log/messages

If "rsyslog" is not logging messages for the cron facility or all facilities, this is a finding.

Vulnerability Number

V-253101

Documentable

False

Rule Version

TOSS-04-040590

Severity Override Guidance

Verify that "rsyslog" is configured to log cron events with the following command:

Note: If another logging package is used, substitute the utility configuration file for "/etc/rsyslog.conf" or "/etc/rsyslog.d/*.conf" files.

$ sudo grep -r cron /etc/rsyslog.conf /etc/rsyslog.d

/etc/rsyslog.conf:*.info;mail.none;authpriv.none;cron.none /var/log/messages
/etc/rsyslog.conf:# Log cron stuff
/etc/rsyslog.conf:cron.* /var/log/cron

If the command does not return a response, check for cron logging all facilities with the following command.

$ sudo grep -r /var/log/messages /etc/rsyslog.conf /etc/rsyslog.d

/etc/rsyslog.conf:*.info;mail.none;authpriv.none;cron.none /var/log/messages

If "rsyslog" is not logging messages for the cron facility or all facilities, this is a finding.

Check Content Reference

M

Target Key

5469