SV-283429r1194981_rule
V-283429
SRG-APP-000516-NDM-000350
ASMP-ND-001100
CAT I
10
Configure the remote syslog host:
cli% setsys RemoteSyslogSecurityHost <hostname> <address-spec> [:port]
Note: The hostname and address are both required. If both IPv4 and IPv6 addresses are supplied, the IPv6 address must be enclosed in []. The default port is 6514 using TLS.
Configure the system to use remote syslog:
cli% setsys RemoteSyslog 1
Verify the system is configured to off-load security syslog events with the following command:
cli% showsys -d
--------------------Remote_Syslog_Status--------------------
Active : 1
General Server : es1-vlan3489-rsyslog.es1-storage.net
General Connection : TLS
RemoteSyslogProfile : None
Security Server : es1-vlan3489-rsyslog.es1-storage.net
Security Connection : TLS
For the options in the "Remote Syslog Status" section:
If "Active" is not "1", this is a finding.
If "Security Server" is not defined, this is a finding.
If "Security Connection" is not "TLS", this is a finding.
V-283429
False
ASMP-ND-001100
Verify the system is configured to off-load security syslog events with the following command:
cli% showsys -d
--------------------Remote_Syslog_Status--------------------
Active : 1
General Server : es1-vlan3489-rsyslog.es1-storage.net
General Connection : TLS
RemoteSyslogProfile : None
Security Server : es1-vlan3489-rsyslog.es1-storage.net
Security Connection : TLS
For the options in the "Remote Syslog Status" section:
If "Active" is not "1", this is a finding.
If "Security Server" is not defined, this is a finding.
If "Security Connection" is not "TLS", this is a finding.
M
5742