SV-235831r627620_rule
V-235831
SRG-APP-000343
DKER-EE-003230
CAT II
10
via CLI:
Linux: As a trusted user on the host operating system, open the /etc/docker/daemon.json file for editing. If the file doesn't exist, it must be created.
Set the "log-driver" property to one of the following: "syslog", "awslogs", "splunk", "gcplogs", "logentries" or "<plugin>" (where <plugin> is the naming of a third-party Docker logging driver plugin). Configure the "log-opts" object as required by the selected "log-driver".
Save the file. Restart the docker daemon.
via CLI:
Linux: Execute the following commands as a trusted user on the host operating system:
cat /etc/docker/daemon.json | grep -i log-driver
Verify that the "log-driver" property is set to one of the following: "syslog", "awslogs", "splunk", "gcplogs", "logentries" or "<plugin>" (where <plugin> is the naming of a third-party Docker logging driver plugin).
If "log-driver" is not set, then this is a finding.
V-235831
False
DKER-EE-003230
via CLI:
Linux: Execute the following commands as a trusted user on the host operating system:
cat /etc/docker/daemon.json | grep -i log-driver
Verify that the "log-driver" property is set to one of the following: "syslog", "awslogs", "splunk", "gcplogs", "logentries" or "<plugin>" (where <plugin> is the naming of a third-party Docker logging driver plugin).
If "log-driver" is not set, then this is a finding.
M
5281