SV-36642r1_rule
V-13688
WG242
WG242 A22
CAT II
10
Configure the web server to ensure the log file data includes the required data elements.
To verify the log settings:
Default UNIX location: /usr/local/apache/logs/access_log
If this directory does not exist, you can search the web server for the httpd.conf file to determine the location of the logs.
Items to be logged are as shown in this sample line in the httpd.conf file:
LogFormat "%a %A %h %H %l %m %s %t %u %U \"%{Referer}i\" " combined
If the web server is not configured to capture the required audit events for all sites and virtual directories, this is a finding.
V-13688
False
WG242 A22
To verify the log settings:
Default UNIX location: /usr/local/apache/logs/access_log
If this directory does not exist, you can search the web server for the httpd.conf file to determine the location of the logs.
Items to be logged are as shown in this sample line in the httpd.conf file:
LogFormat "%a %A %h %H %l %m %s %t %u %U \"%{Referer}i\" " combined
If the web server is not configured to capture the required audit events for all sites and virtual directories, this is a finding.
M
Web Administrator
161