SV-213509r615939_rule
V-213509
SRG-APP-000097-AS-000060
JBOS-AS-000120
CAT II
10
Configure log formatter to audit application activity so individual application activity can be identified.
Application logs are a configurable variable. Interview the system admin, and have them identify the applications that are running on the application server. Have the system admin identify the log files/location where application activity is stored.
Review the log files to ensure each application is uniquely identified within the logs or each application has its own unique log file.
Generate application activity by either authenticating to the application or generating an auditable event, and ensure the application activity is recorded in the log file. Recently time stamped application events are suitable evidence of compliance.
If the log records do not indicate which application hosted on the application server generated the event, or if no events are recorded related to application activity, this is a finding.
V-213509
False
JBOS-AS-000120
Application logs are a configurable variable. Interview the system admin, and have them identify the applications that are running on the application server. Have the system admin identify the log files/location where application activity is stored.
Review the log files to ensure each application is uniquely identified within the logs or each application has its own unique log file.
Generate application activity by either authenticating to the application or generating an auditable event, and ensure the application activity is recorded in the log file. Recently time stamped application events are suitable evidence of compliance.
If the log records do not indicate which application hosted on the application server generated the event, or if no events are recorded related to application activity, this is a finding.
M
3987