Check: ENS-CO-000106
Trellix ENS 10.x STIG:
ENS-CO-000106
(in versions v2 r14 through v2 r5)
Title
(U) The Trellix ENS Common Options Client Logging scan log file size must be configured to be between 10-100MB. (Cat II impact)
Discussion
(U) While logging is imperative to forensic analysis, logs could grow to the point of impacting disk space on the system. To avoid the risk of logs growing to the size of impacting the operating system, the log size will be restricted but must also be large enough to retain forensic value.
Check Content
(U) Access the ePO server console. Select Menu >> Policy >> Policy Catalog From the "Product" list, select "Endpoint Security Common". From the "Category" list, select "Options". Select each configured Options policy. Click the "Show Advanced" button. Verify Client Logging >> Enable Activity Logging >> Limit size (MB) of each activity log file is configured to between "10" and "100" MB. If Client Logging >> Enable Activity Logging >> Limit size (MB) of each activity log file is configured for less than "10" MB or more than "100" MB, this is a finding.
Fix Text
(U) Access the ePO server console. Select Menu >> Policy >> Policy Catalog From the "Product" list, select "Endpoint Security Common". From the "Category" list, select "Options". Select each configured Options policy. Click the "Show Advanced" button. Configure Client Logging >> Enable Activity Logging >> Limit size (MB) of each activity log file to between "10" and "100" MB. Click "Save".
Additional Identifiers
Rule ID: SV-228229r944443_rule
Vulnerability ID: V-228229
Group Title: SRG-APP-000358
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001851 |
The information system off-loads audit records per organization-defined frequency onto a different system or media than the system being audited. |
Controls
Number | Title |
---|---|
AU-4 (1) |
Transfer To Alternate Storage |