STIGQter STIGQter: STIG Summary: Dragos Platform 2.x Security Technical Implementation Guide Version: 1 Release: 6 Benchmark Date: 01 Apr 2026:

The Dragos Platform must be configured to send backup audit records.

DISA Rule

SV-270944r1107127_rule

Vulnerability Number

V-270944

Group Title

SRG-APP-000125

Rule Version

DRAG-OT-000490

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Create Syslog server and Rule.

1. Create a Syslog server on a third-party device. The steps may vary depending on the chosen Syslog server software.

2. Create a syslog server output in the Dragos UI.
Navigate to Admin >> Integrations.
Click "LAUNCH" in the Syslog section.
Click "ADD NEW SERVER".
Enter third-party server information, select TLS or mTLS in the protocol dropdown, and click "NEXT". Note: This step may require TLS certificate generation.
Input Message Template.
Click "SAVE".

3. Create a rule.
Navigate to Notification >> RULES Tab.
Click "NEW RULE".
Fill in Name and Processing Order.
Select For Rule Criteria:
If ANY of the following - "Notification Type" "Equals" "System"
Action = Send Syslog (third-party server)
Click "SAVE".

Check Contents

Verify third-party server is used to offload audit records.

1. Check for a configured Syslog Server. In the UI, navigate to Admin >> Integrations.

Click "LAUNCH" in the Syslog section.

If a Syslog Server is not listed or Status is not connected, this is a finding.

If the protocol of the Syslog Server is not TLS or mTLS, this is a finding.

2. Check for an export rule. In the UI, navigate to Notification >> RULES Tab.

Verify a rule exists and has the following:
Action = "Send Syslog (<your syslog server>)"
Criteria = "IF Notification Type equals System"

If this rule does not exist with the correct Action and Criteria, this is a finding.

Vulnerability Number

V-270944

Documentable

False

Rule Version

DRAG-OT-000490

Severity Override Guidance

Verify third-party server is used to offload audit records.

1. Check for a configured Syslog Server. In the UI, navigate to Admin >> Integrations.

Click "LAUNCH" in the Syslog section.

If a Syslog Server is not listed or Status is not connected, this is a finding.

If the protocol of the Syslog Server is not TLS or mTLS, this is a finding.

2. Check for an export rule. In the UI, navigate to Notification >> RULES Tab.

Verify a rule exists and has the following:
Action = "Send Syslog (<your syslog server>)"
Criteria = "IF Notification Type equals System"

If this rule does not exist with the correct Action and Criteria, this is a finding.

Check Content Reference

M

Target Key

5675