SV-79559r1_rule
V-65069
SRG-APP-000089-NDM-000221
WSDP-NM-000022
CAT II
10
Privileged account user logon to default domain
In the search field, enter “Log Target”.
From the search results, click “Log Target”.
Click “Add”.
Name: enter the name of the log target (e.g., targetDodEvents)
Target Type: File
Log Format: XML
Timestamp format: Syslog
Destination Configuration: File Name: logstore:///dodEvents.log
Log Size: 1024
Archive Mode: Rotate
Number of Rotations: 6
Click on the “Event Filters” Tab.
Event Subscription Filter, click “Select Code”; select an Event Code from the list in the popup window.
Click the “Add” button. Repeat the process until all desired event codes have been added.
Click “Apply” to save the changes to the running configuration.
Click “Save Configuration” to save the changes to the persisted configuration.
Control Panel >> View Logs
Select “DOD-EventsLog” from the drop-down list at the top of the page. If the log is empty, this is a finding.
V-65069
False
WSDP-NM-000022
Control Panel >> View Logs
Select “DOD-EventsLog” from the drop-down list at the top of the page. If the log is empty, this is a finding.
M
2861