Check: SRG-APP-000086-AU-000390
Central Log Server SRG:
SRG-APP-000086-AU-000390
(in versions v2 r2 through v1 r0.1)
Title
Where multiple log servers are installed in the enclave, each log server must be configured to aggregate log records to a central aggregation server or other consolidated events repository. (Cat II impact)
Discussion
Log servers (e.g., syslog servers) are often used on network segments to consolidate from the devices and hosts on that network segment. However, this does not achieve compliance with the DoD requirement for a centralized enclave log server. To comply with this requirement, create a central log server that aggregates multiple log servers or use another method to ensure log analysis and management is centrally managed and available to enterprise forensics and analysis tools. This server is often called a log aggregator, SIEM, or events server.
Check Content
Examine the network architecture and documentation. If the log server being reviewed is one of multiple log servers in the enclave or on a network segment, verify that an aggregation server exists and that the log server under review is configured to send records received from the host and devices to the aggregation server or centralized SIEM/events sever. Where multiple log servers are installed in the enclave, if each log server is not configured to send log records to a central aggregation server or other consolidated events repository, this is a finding.
Fix Text
Where multiple log servers are installed in the enclave, configure each log server to forward logs to a consolidated aggregation server.
Additional Identifiers
Rule ID: SV-206451r395700_rule
Vulnerability ID: V-206451
Group Title: SRG-APP-000086
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000174 |
The information system compiles audit records from organization-defined information system components into a system-wide (logical or physical) audit trail that is time-correlated to within an organization-defined level of tolerance for relationship between time stamps of individual records in the audit trail. |
Controls
Number | Title |
---|---|
AU-12 (1) |
System-Wide / Time-Correlated Audit Trail |