SV-261917r1000962_rule
V-261917
SRG-APP-000356-DB-000314
CD16-00-007000
CAT II
10
Note: The following instructions use the PGDATA and PGVER environment variables. Refer to APPENDIX-F for instructions on configuring PGDATA and APPENDIX-H for PGVER.
To ensure logging is enabled, review supplementary content APPENDIX-C for instructions on enabling logging.
With logging enabled, as the database owner (shown here as "postgres"), configure the following parameters in postgresql.conf:
Note: Consult the organization on how syslog facilities are defined in the syslog daemon configuration.
$ sudo su - postgres
$ vi ${PGDATA?}/postgresql.conf
log_destination = 'syslog'
syslog_facility = 'LOCAL0'
syslog_ident = 'postgres'
As the system administrator, reload the server with the new configuration:
$ sudo systemctl reload postgresql-${PGVER?}
On Unix systems, PostgreSQL can be configured to use stderr, csvlog, and syslog. To send logs to a centralized location, syslog should be used.
As the database owner (shown here as "postgres"), ensure PostgreSQL uses syslog by running the following SQL:
$ sudo su - postgres
$ psql -c "SHOW log_destination"
As the database owner (shown here as "postgres"), check to which log facility PostgreSQL is configured by running the following SQL:
$ sudo su - postgres
$ psql -c "SHOW syslog_facility"
Check with the organization to refer to how syslog facilities are defined in their organization.
If PostgreSQL audit records are not written directly to or systematically transferred to a centralized log management system, this is a finding.
V-261917
False
CD16-00-007000
On Unix systems, PostgreSQL can be configured to use stderr, csvlog, and syslog. To send logs to a centralized location, syslog should be used.
As the database owner (shown here as "postgres"), ensure PostgreSQL uses syslog by running the following SQL:
$ sudo su - postgres
$ psql -c "SHOW log_destination"
As the database owner (shown here as "postgres"), check to which log facility PostgreSQL is configured by running the following SQL:
$ sudo su - postgres
$ psql -c "SHOW syslog_facility"
Check with the organization to refer to how syslog facilities are defined in their organization.
If PostgreSQL audit records are not written directly to or systematically transferred to a centralized log management system, this is a finding.
M
5598