SV-282384r1200132_rule
V-282384
SRG-OS-000032-GPOS-00013
TOSS-05-000379
CAT II
10
Add or update the following lines to the "/etc/rsyslog.conf" file:
auth.*;authpriv.*;daemon.* /var/log/secure
Restart the "rsyslog" service for the changes to take effect using the following command:
$ sudo systemctl restart rsyslog.service
Verify TOSS 5 monitors all remote access methods.
Check that remote access methods are being logged using the following command:
$ grep -rE '(auth.\*|authpriv.\*|daemon.\*)' /etc/rsyslog.conf
/etc/rsyslog.conf:authpriv.*
If "auth.*", "authpriv.*" or "daemon.*" are not configured to be logged, this is a finding.
V-282384
False
TOSS-05-000379
Verify TOSS 5 monitors all remote access methods.
Check that remote access methods are being logged using the following command:
$ grep -rE '(auth.\*|authpriv.\*|daemon.\*)' /etc/rsyslog.conf
/etc/rsyslog.conf:authpriv.*
If "auth.*", "authpriv.*" or "daemon.*" are not configured to be logged, this is a finding.
M
5738