STIGQter STIGQter: STIG Summary: vRealize - Cassandra Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 05 Jun 2017:

The Cassandra Server must generate time stamps, for audit records and application data, with a minimum granularity of one second.

DISA Rule

SV-87309r1_rule

Vulnerability Number

V-72677

Group Title

SRG-APP-000375-DB-000323

Rule Version

VROM-CS-000225

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Cassandra Server to generate time stamps, for audit records and application data, with a minimum granularity of one second.

Navigate to and open /usr/lib/vmware-vcops/user/conf/cassandra/logback.xml.

Navigate to the <appender> node with the name="FILE" attribute.

Navigate to <encoder> node.

Edit the <pattern> to look like the below.
<pattern>%-5level [%thread] %date{ISO8601, UTC} %F:%L - %msg%n</pattern>

Check Contents

Review the Cassandra Server settings to ensure time stamps, for audit records and application data, with a minimum granularity of one second are generated.

Navigate to and open /usr/lib/vmware-vcops/user/conf/cassandra/logback.xml.

Navigate to the <appender> node with the name="FILE" attribute.

Navigate to <encoder> node.

If the <pattern> node does not look like the expected result, this is a finding.

Expected result:
<pattern>%-5level [%thread] %date{ISO8601, UTC} %F:%L - %msg%n</pattern>

Vulnerability Number

V-72677

Documentable

False

Rule Version

VROM-CS-000225

Severity Override Guidance

Review the Cassandra Server settings to ensure time stamps, for audit records and application data, with a minimum granularity of one second are generated.

Navigate to and open /usr/lib/vmware-vcops/user/conf/cassandra/logback.xml.

Navigate to the <appender> node with the name="FILE" attribute.

Navigate to <encoder> node.

If the <pattern> node does not look like the expected result, this is a finding.

Expected result:
<pattern>%-5level [%thread] %date{ISO8601, UTC} %F:%L - %msg%n</pattern>

Check Content Reference

M

Target Key

3179

Comments