SV-239398r674688_rule
V-239398
SRG-APP-000358-WSR-000163
VCEM-67-000027
CAT II
10
Navigate to and open:
/etc/vmware-syslog/stig-services-eam.conf.
Create the file if it does not exist.
Set the contents of the file as follows:
input(type="imfile"
File="/var/log/vmware/eam/eam.log"
Tag="eam-main"
Severity="info"
Facility="local0")
input(type="imfile"
File="/var/log/vmware/eam/web/localhost_access_log*.txt"
Tag="eam-access"
Severity="info"
Facility="local0")
input(type="imfile"
File="/var/log/vmware/eam/jvm.log.std*"
Tag="eam-stdout"
Severity="info"
Facility="local0")
input(type="imfile"
File="/var/log/vmware/eam/web/catalina*.log"
Tag="eam-catalina"
Severity="info"
Facility="local0")
input(type="imfile"
File="/var/log/vmware/eam/web/localhost.*.log"
Tag="eam-catalina"
Severity="info"
Facility="local0")
input(type="imfile"
File="/var/log/vmware/firstboot/eam_firstboot.py*.log"
Tag="eam-firstboot"
Severity="info"
Facility="local0")
At the command prompt, execute the following command:
# grep -v "^#" /etc/vmware-syslog/stig-services-eam.conf
Expected result:
input(type="imfile"
File="/var/log/vmware/eam/eam.log"
Tag="eam-main"
Severity="info"
Facility="local0")
input(type="imfile"
File="/var/log/vmware/eam/web/localhost_access_log*.txt"
Tag="eam-access"
Severity="info"
Facility="local0")
input(type="imfile"
File="/var/log/vmware/eam/jvm.log.std*"
Tag="eam-stdout"
Severity="info"
Facility="local0")
input(type="imfile"
File="/var/log/vmware/eam/web/catalina*.log"
Tag="eam-catalina"
Severity="info"
Facility="local0")
input(type="imfile"
File="/var/log/vmware/eam/web/localhost.*.log"
Tag="eam-catalina"
Severity="info"
Facility="local0")
input(type="imfile"
File="/var/log/vmware/firstboot/eam_firstboot.py*.log"
Tag="eam-firstboot"
Severity="info"
Facility="local0") File="/var/log/vmware/firstboot/eam_firstboot.py*.log"
Tag="eam-firstboot"
Severity="info"
Facility="local0")
If the file does not exist, this is a finding.
If the output of the command does not match the expected result, this is a finding.
V-239398
False
VCEM-67-000027
At the command prompt, execute the following command:
# grep -v "^#" /etc/vmware-syslog/stig-services-eam.conf
Expected result:
input(type="imfile"
File="/var/log/vmware/eam/eam.log"
Tag="eam-main"
Severity="info"
Facility="local0")
input(type="imfile"
File="/var/log/vmware/eam/web/localhost_access_log*.txt"
Tag="eam-access"
Severity="info"
Facility="local0")
input(type="imfile"
File="/var/log/vmware/eam/jvm.log.std*"
Tag="eam-stdout"
Severity="info"
Facility="local0")
input(type="imfile"
File="/var/log/vmware/eam/web/catalina*.log"
Tag="eam-catalina"
Severity="info"
Facility="local0")
input(type="imfile"
File="/var/log/vmware/eam/web/localhost.*.log"
Tag="eam-catalina"
Severity="info"
Facility="local0")
input(type="imfile"
File="/var/log/vmware/firstboot/eam_firstboot.py*.log"
Tag="eam-firstboot"
Severity="info"
Facility="local0") File="/var/log/vmware/firstboot/eam_firstboot.py*.log"
Tag="eam-firstboot"
Severity="info"
Facility="local0")
If the file does not exist, this is a finding.
If the output of the command does not match the expected result, this is a finding.
M
5328