SV-253933r961824_rule
V-253933
SRG-APP-000503-NDM-000320
JUEX-NM-000560
CAT II
10
Configure the network device to generate audit records when successful/unsuccessful logon attempts occur.
set system syslog file <file name> any info
set system syslog file <file name> structured-data << (Optional) Only if structured data format is required
set system syslog host <external syslog address> authorization info
set system syslog host <external syslog address> structured-data << (Optional) Only if structured data format is required
set system syslog time-format <(year|millisecond)>
Determine if the network device generates audit records when successful/unsuccessful logon attempts occur.
Junos logs all logon attempts via the "authorization" syslog facility (or facility "any"). Verify logging level "any info" or "authorization info" is configured.
[edit system syslog]
file <file name> {
authorization info;
}
host <external syslog address> {
any info;
}
time-format year millisecond;
Syslog outputs in standard format unless the "structured-data" directive is configured. Verify the "structured-data" command for all files and external syslog servers requiring that format. For example:
[edit system syslog]
host <syslog address> {
authorization info;
structured-data;
}
file <file name> {
any info;
structured-data;
}
If it does not generate audit records when successful/unsuccessful logon attempts occur, this is a finding.
V-253933
False
JUEX-NM-000560
Determine if the network device generates audit records when successful/unsuccessful logon attempts occur.
Junos logs all logon attempts via the "authorization" syslog facility (or facility "any"). Verify logging level "any info" or "authorization info" is configured.
[edit system syslog]
file <file name> {
authorization info;
}
host <external syslog address> {
any info;
}
time-format year millisecond;
Syslog outputs in standard format unless the "structured-data" directive is configured. Verify the "structured-data" command for all files and external syslog servers requiring that format. For example:
[edit system syslog]
host <syslog address> {
authorization info;
structured-data;
}
file <file name> {
any info;
structured-data;
}
If it does not generate audit records when successful/unsuccessful logon attempts occur, this is a finding.
M
5477