SV-214123r508027_rule
V-214123
SRG-APP-000092-DB-000208
PGS9-00-008600
CAT II
10
Configure PostgreSQL to enable auditing.
To ensure that logging is enabled, review supplementary content APPENDIX-C for instructions on enabling logging.
For session logging we suggest using pgaudit. For instructions on how to setup pgaudit, see supplementary content APPENDIX-B.
As the database administrator (shown here as "postgres"), check the current settings by running the following SQL:
$ sudo su - postgres
$ psql -c "SHOW shared_preload_libraries"
If pgaudit is not in the current setting, this is a finding.
As the database administrator (shown here as "postgres"), check the current settings by running the following SQL:
$ psql -c "SHOW log_destination"
If stderr or syslog are not in the current setting, this is a finding.
V-214123
False
PGS9-00-008600
As the database administrator (shown here as "postgres"), check the current settings by running the following SQL:
$ sudo su - postgres
$ psql -c "SHOW shared_preload_libraries"
If pgaudit is not in the current setting, this is a finding.
As the database administrator (shown here as "postgres"), check the current settings by running the following SQL:
$ psql -c "SHOW log_destination"
If stderr or syslog are not in the current setting, this is a finding.
M
3994