SV-259185r1210431_rule
V-259185
SRG-APP-000515-DB-000318
VCPG-80-000122
CAT II
10
Navigate to and open:
/etc/vmware-syslog/vmware-services-vmware-vpostgres.conf
Create the file if it does not exist.
Set the contents of the file as follows:
# vmware-vpostgres first logs stdout, before loading configuration
input(type="imfile"
File="/var/log/vmware/vpostgres/serverlog.stdout"
Tag="vpostgres-first"
Severity="info"
Facility="local0"
deleteStateOnFileDelete="on"
reopenOnTruncate="on")
# vmware-vpostgres first logs stderr, before loading configuration
input(type="imfile"
File="/var/log/vmware/vpostgres/serverlog.stderr"
Tag="vpostgres-first"
Severity="info"
Facility="local0"
deleteStateOnFileDelete="on"
reopenOnTruncate="on")
# vmware-vpostgres logs
input(type="imfile"
File="/var/log/vmware/vpostgres/postgresql-*.log"
Tag="vpostgres"
Severity="info"
Facility="local0"
deleteStateOnFileDelete="on"
reopenOnTruncate="on")
Navigate to and open:
/etc/vmware-syslog/vmware-services-vmware-postgres-archiver.conf
Create the file if it does not exist.
Set the contents of the file as follows:
# vmware-postgres-archiver stdout log
input(type="imfile"
File="/var/log/vmware/vpostgres/pg_archiver.log.stdout"
Tag="postgres-archiver"
Severity="info"
Facility="local0"
deleteStateOnFileDelete="on"
reopenOnTruncate="on")
# vmware-postgres-archiver stderr log
input(type="imfile"
File="/var/log/vmware/vpostgres/pg_archiver.log.stderr"
Tag="postgres-archiver"
Severity="info"
Facility="local0"
deleteStateOnFileDelete="on"
reopenOnTruncate="on")
By default, a vmware-services-vmware-vpostgres.conf rsyslog and vmware-services-vmware-postgres-archiver.conf configuration file include the service logs when syslog is configured on vCenter, but they must be verified.
At the command prompt, run the following command:
# cat /etc/vmware-syslog/vmware-services-vmware-vpostgres.conf
Expected result:
# vmware-vpostgres first logs stdout, before loading configuration
input(type="imfile"
File="/var/log/vmware/vpostgres/serverlog.stdout"
Tag="vpostgres-first"
Severity="info"
Facility="local0"
deleteStateOnFileDelete="on"
reopenOnTruncate="on")
# vmware-vpostgres first logs stderr, before loading configuration
input(type="imfile"
File="/var/log/vmware/vpostgres/serverlog.stderr"
Tag="vpostgres-first"
Severity="info"
Facility="local0"
deleteStateOnFileDelete="on"
reopenOnTruncate="on")
# vmware-vpostgres logs
input(type="imfile"
File="/var/log/vmware/vpostgres/postgresql-*.log"
Tag="vpostgres"
Severity="info"
Facility="local0"
deleteStateOnFileDelete="on"
reopenOnTruncate="on")
Note: If the entries for "deleteStateOnFileDelete" and "reopenOnTruncate" do not exist, this is not a finding.
If the output does not match the expected result, this is a finding.
At the command prompt, run the following command:
# cat /etc/vmware-syslog/vmware-services-vmware-postgres-archiver.conf
Expected result:
# vmware-postgres-archiver stdout log
input(type="imfile"
File="/var/log/vmware/vpostgres/pg_archiver.log.stdout"
Tag="postgres-archiver"
Severity="info"
Facility="local0"
deleteStateOnFileDelete="on"
reopenOnTruncate="on")
# vmware-postgres-archiver stderr log
input(type="imfile"
File="/var/log/vmware/vpostgres/pg_archiver.log.stderr"
Tag="postgres-archiver"
Severity="info"
Facility="local0"
deleteStateOnFileDelete="on"
reopenOnTruncate="on")
Note: If the entries for "deleteStateOnFileDelete" and "reopenOnTruncate" do not exist, this is not a finding.
If the output does not match the expected result, this is a finding.
V-259185
False
VCPG-80-000122
By default, a vmware-services-vmware-vpostgres.conf rsyslog and vmware-services-vmware-postgres-archiver.conf configuration file include the service logs when syslog is configured on vCenter, but they must be verified.
At the command prompt, run the following command:
# cat /etc/vmware-syslog/vmware-services-vmware-vpostgres.conf
Expected result:
# vmware-vpostgres first logs stdout, before loading configuration
input(type="imfile"
File="/var/log/vmware/vpostgres/serverlog.stdout"
Tag="vpostgres-first"
Severity="info"
Facility="local0"
deleteStateOnFileDelete="on"
reopenOnTruncate="on")
# vmware-vpostgres first logs stderr, before loading configuration
input(type="imfile"
File="/var/log/vmware/vpostgres/serverlog.stderr"
Tag="vpostgres-first"
Severity="info"
Facility="local0"
deleteStateOnFileDelete="on"
reopenOnTruncate="on")
# vmware-vpostgres logs
input(type="imfile"
File="/var/log/vmware/vpostgres/postgresql-*.log"
Tag="vpostgres"
Severity="info"
Facility="local0"
deleteStateOnFileDelete="on"
reopenOnTruncate="on")
Note: If the entries for "deleteStateOnFileDelete" and "reopenOnTruncate" do not exist, this is not a finding.
If the output does not match the expected result, this is a finding.
At the command prompt, run the following command:
# cat /etc/vmware-syslog/vmware-services-vmware-postgres-archiver.conf
Expected result:
# vmware-postgres-archiver stdout log
input(type="imfile"
File="/var/log/vmware/vpostgres/pg_archiver.log.stdout"
Tag="postgres-archiver"
Severity="info"
Facility="local0"
deleteStateOnFileDelete="on"
reopenOnTruncate="on")
# vmware-postgres-archiver stderr log
input(type="imfile"
File="/var/log/vmware/vpostgres/pg_archiver.log.stderr"
Tag="postgres-archiver"
Severity="info"
Facility="local0"
deleteStateOnFileDelete="on"
reopenOnTruncate="on")
Note: If the entries for "deleteStateOnFileDelete" and "reopenOnTruncate" do not exist, this is not a finding.
If the output does not match the expected result, this is a finding.
M
5570