STIGQter STIGQter: STIG Summary: Omnissa WS1 UEM Server Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 May 2026:

The Omnissa WS1 UEM server must be configured to transfer Omnissa WS1 UEM server logs to another server for storage, analysis, and reporting. Note: Omnissa WS1 UEM server logs include logs of UEM events and logs transferred to the Omnissa WS1 UEM server by UEM agents of managed devices.

DISA Rule

SV-284305r1224048_rule

Vulnerability Number

V-284305

Group Title

SRG-APP-000358-UEM-000228

Rule Version

OMW1-00-006500

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Workspace ONE UEM server to transfer Workspace ONE UEM server logs to another server for storage, analysis, and reporting.

On the MDM console, do the following:

1. Authenticate to the Workspace ONE UEM console as the administrator.
2. Navigate to Groups & Settings >> All Settings >> System >> Enterprise Integration >> Syslog.
3. Set "Syslog Integration" to "ENABLED".
4. Configure syslog server hostname, protocol, port, syslog facility, message tag, message content according to organizational standards.
5. Click "SAVE".
6. Verify changes save successfully and Workspace ONE UEM server can transfer audit logs to the new syslog server.

Check Contents

Review the Workspace ONE UEM server configuration settings and verify the server is configured to transfer Workspace ONE UEM server logs to another server for storage, analysis, and reporting.

On the MDM console, do the following:

1. Authenticate to the Workspace ONE UEM console as the administrator.
2. Navigate to Groups & Settings >> All Settings >> System >> Enterprise Integration >> Syslog.
3. If "Syslog Integration" is set to "DISABLED", this is a finding.
4. Examine the syslog configuration (server hostname, protocol, port, syslog facility, message tag, message content) for conformance with operational standards.

If any are not set according to the standards, this is a finding.

Note: Workspace ONE UEM server logs include logs of MDM events and logs transferred to the Workspace ONE UEM server by MDM agents of managed devices.

Vulnerability Number

V-284305

Documentable

False

Rule Version

OMW1-00-006500

Severity Override Guidance

Review the Workspace ONE UEM server configuration settings and verify the server is configured to transfer Workspace ONE UEM server logs to another server for storage, analysis, and reporting.

On the MDM console, do the following:

1. Authenticate to the Workspace ONE UEM console as the administrator.
2. Navigate to Groups & Settings >> All Settings >> System >> Enterprise Integration >> Syslog.
3. If "Syslog Integration" is set to "DISABLED", this is a finding.
4. Examine the syslog configuration (server hostname, protocol, port, syslog facility, message tag, message content) for conformance with operational standards.

If any are not set according to the standards, this is a finding.

Note: Workspace ONE UEM server logs include logs of MDM events and logs transferred to the Workspace ONE UEM server by MDM agents of managed devices.

Check Content Reference

M

Target Key

5751