SV-223184r513247_rule
V-223184
SRG-APP-000029-NDM-000211
JUSX-DM-000018
CAT II
10
Configure at least one external syslog host is configured to log facility change-log or any, and severity info or any.
[edit system syslog]
set host <syslog server address> any <info | any>
-OR-
[edit]
set host <syslog server address> change-log <info | any>
Verify the device logs change-log events of severity info or any to an external syslog server.
[edit]
show system syslog
host <syslog server address> {
any <info | any>;
source-address <device address>;
}
-OR-
host <syslog server address> {
change-log <info | any>;
source-address <device address>;
}
If an external syslog host is not configured to log facility change-log severity <info | any>, or configured for facility any severity <info | any>, this is a finding.
V-223184
False
JUSX-DM-000018
Verify the device logs change-log events of severity info or any to an external syslog server.
[edit]
show system syslog
host <syslog server address> {
any <info | any>;
source-address <device address>;
}
-OR-
host <syslog server address> {
change-log <info | any>;
source-address <device address>;
}
If an external syslog host is not configured to log facility change-log severity <info | any>, or configured for facility any severity <info | any>, this is a finding.
M
4098