Check: VCPF-67-000027
VMware vSphere 6.7 Perfcharts Tomcat STIG:
VCPF-67-000027
(in versions v1 r3 through v1 r1)
Title
Rsyslog must be configured to monitor and ship Performance Charts log files. (Cat II impact)
Discussion
Performance Charts produces a handful of logs that must be offloaded from the originating system. This information can then be used for diagnostic purposes, forensics purposes, or other purposes relevant to ensuring the availability and integrity of the hosted application. Satisfies: SRG-APP-000358-WSR-000163, SRG-APP-000125-WSR-000071
Check Content
At the command prompt, execute the following command: # grep -v "^#" /etc/vmware-syslog/stig-services-perfcharts.conf Expected result: input(type="imfile" File="/var/log/vmware/perfcharts/localhost_access_log.*.txt" Tag="perfcharts-localhost_access" Severity="info" Facility="local0") input(type="imfile" File="/var/log/vmware/perfcharts/vmware-perfcharts-runtime.log.std*" Tag="perfcharts-runtime" Severity="info" Facility="local0") If the file does not exist, this is a finding. If the output of the command does not match the expected result, this is a finding.
Fix Text
Navigate to and open /etc/vmware-syslog/stig-services-perfcharts.conf. Create the file if it does not exist. Set the contents of the file as follows: input(type="imfile" File="/var/log/vmware/perfcharts/localhost_access_log.*.txt" Tag="perfcharts-localhost_access" Severity="info" Facility="local0") input(type="imfile" File="/var/log/vmware/perfcharts/vmware-perfcharts-runtime.log.std*" Tag="perfcharts-runtime" Severity="info" Facility="local0")
Additional Identifiers
Rule ID: SV-239428r879731_rule
Vulnerability ID: V-239428
Group Title: SRG-APP-000358-WSR-000163
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001348 |
The information system backs up audit records on an organization-defined frequency onto a different system or system component than the system or component being audited. |
CCI-001851 |
The information system off-loads audit records per organization-defined frequency onto a different system or media than the system being audited. |