SV-230943r615886_rule
V-230943
SRG-APP-000515-NDM-000325
FORE-NM-000150
CAT III
10
Configure the syslog.
1. Log on to Forescout Administrator UI with admin or operator credentials.
2. From the menu, select Tools >> Options >> Modules >> Syslog >> Send Events To.
3. Click "Add".
4. Enter the IP address of the site's centralized syslog.
5. Check "Use TLS".
6. Configure OCSP, Identity, Facility, and Severity as required by the SSP.
Verify the syslog.
1. Log on to Forescout Administrator UI with admin or operator credentials.
2. From the menu, select Tools >> Options >> Modules >> Syslog >> Send Events To.
3. Click the IP address of the site's centralized syslog server.
4. Verify "Use TLS" is checked.
5. Verify OCSP, Identity, Facility, and Severity, as required by the SSP, are configured.
If the site's syslog server is not configured or if it is not configure to use TLS and OCSP, this is a finding.
V-230943
False
FORE-NM-000150
Verify the syslog.
1. Log on to Forescout Administrator UI with admin or operator credentials.
2. From the menu, select Tools >> Options >> Modules >> Syslog >> Send Events To.
3. Click the IP address of the site's centralized syslog server.
4. Verify "Use TLS" is checked.
5. Verify OCSP, Identity, Facility, and Severity, as required by the SSP, are configured.
If the site's syslog server is not configured or if it is not configure to use TLS and OCSP, this is a finding.
M
5245