SV-239112r675144_rule
V-239112
SRG-OS-000205-GPOS-00083
PHTN-67-000040
CAT II
10
Open /etc/vmware-syslog/syslog.conf with a text editor.
Remove any existing content and create a new remote server configuration line.
For UDP:
*.* @<syslog server>:port;RSYSLOG_syslogProtocol23Format
For TCP:
*.* @@<syslog server>:port;RSYSLOG_syslogProtocol23Format
OR
Navigate to https://<hostname>:5480 to access the VAMI.
Authenticate and navigate to "Syslog Configuration".
Click "Edit" in the top right.
Configure a remote syslog server and click "OK".
At the command line, execute the following command:
# cat /etc/vmware-syslog/syslog.conf
The output should be similar to the following:
*.* @<syslog server>:port;RSYSLOG_syslogProtocol23Format
If no line is returned or if the line is commented or no valid syslog server is specified, this is a finding.
OR
Navigate to https://<hostname>:5480 to access the Virtual Appliance Management Interface (VAMI). Authenticate and navigate to "Syslog Configuration".
If no site-specific syslog server is configured, this is a finding.
V-239112
False
PHTN-67-000040
At the command line, execute the following command:
# cat /etc/vmware-syslog/syslog.conf
The output should be similar to the following:
*.* @<syslog server>:port;RSYSLOG_syslogProtocol23Format
If no line is returned or if the line is commented or no valid syslog server is specified, this is a finding.
OR
Navigate to https://<hostname>:5480 to access the Virtual Appliance Management Interface (VAMI). Authenticate and navigate to "Syslog Configuration".
If no site-specific syslog server is configured, this is a finding.
M
5323