AOS must be configured to send log data to at least two central log servers for the purpose of forwarding alerts to the administrators and the information system security officer (ISSO).
DISA Rule
SV-266977r1039952_rule
Vulnerability Number
V-266977
Group Title
SRG-APP-000516-NDM-000350
Rule Version
ARBA-ND-000350
Severity
CAT I
CCI(s)
- CCI-001851 - Transfer audit logs per organization-defined frequency to a different system, system component, or media than the system or system component conducting the logging.
- CCI-001664 - Recognize only session identifiers that are system-generated.
Weight
10
Fix Recommendation
Configure AOS with the following commands:
For two or more central syslog servers:
configure terminal
logging <IPv4 or IPv6 address>
write memory
Check Contents
Verify the AOS configuration with the following command:
show logging server
If at least two central log servers are not configured, this is a finding.
Vulnerability Number
V-266977
Documentable
False
Rule Version
ARBA-ND-000350
Severity Override Guidance
Verify the AOS configuration with the following command:
show logging server
If at least two central log servers are not configured, this is a finding.
Check Content Reference
M
Target Key
5648