SV-237059r639624_rule
V-237059
SRG-NET-000511-ALG-000051
AADC-AG-000140
CAT III
10
Since the Audit log is separate from the Event log, it must have its own target to write messages to:
logging auditlog host [ipaddr | hostname][facility facility-name]
“ipaddr | hostname” is the IP address or hostname of the server.
“facility-name” is the name of a log facility.
Review the device configuration.
The following command shows the portion of the device configuration that includes the string "host":
show run | inc host
If the output does not display the "logging auditlog host" commands, this is a finding.
The following command shows the logging policy:
show log policy
If Syslog logging is disabled, this is a finding.
V-237059
False
AADC-AG-000140
Review the device configuration.
The following command shows the portion of the device configuration that includes the string "host":
show run | inc host
If the output does not display the "logging auditlog host" commands, this is a finding.
The following command shows the logging policy:
show log policy
If Syslog logging is disabled, this is a finding.
M
5285