SV-89611r1_rule
V-74937
SRG-APP-000108-NDM-000232
MQMH-ND-000340
CAT II
10
Log on to the MQ Appliance CLI as a privileged user.
Configure a syslog target.
To enter global configuration mode, enter "config".
To create a syslog target, enter:
logging target <logging target name>
type syslog
admin-state enabled
local-address <MQ Appliance IP>
remote-address <syslog server IP>
remote-port <syslog server port>
event audit info
event auth notice
event mgmt notice
event cli notice
event user notice
event system error
exit
write mem
y
At the syslog server, set up event notification triggers for the following event codes: 0x80c0006a, 0x82400067, 0x00330034, 0x80400080.
Log on to the MQ Appliance CLI as a privileged user.
Enter:
co
show logging target
All configured logging targets will be displayed. Verify:
- This list includes a remote syslog notification target; and
- It includes all desired log event source and log level parameters:
event audit info
event auth notice
event mgmt notice
event cli notice
event user notice
event system error
Configuring notification of events occurring at the external logging server is the responsibility of the administrator.
Ask the system admin to provide evidence the required alert triggers for the following event codes: 0x80c0006a, 0x82400067, 0x00330034, 0x80400080 have been set up and the ISSO and SA at a minimum are alerted.
If there is no evidence that alerts are sent in the event of an audit processing failure, this is a finding.
V-74937
False
MQMH-ND-000340
Log on to the MQ Appliance CLI as a privileged user.
Enter:
co
show logging target
All configured logging targets will be displayed. Verify:
- This list includes a remote syslog notification target; and
- It includes all desired log event source and log level parameters:
event audit info
event auth notice
event mgmt notice
event cli notice
event user notice
event system error
Configuring notification of events occurring at the external logging server is the responsibility of the administrator.
Ask the system admin to provide evidence the required alert triggers for the following event codes: 0x80c0006a, 0x82400067, 0x00330034, 0x80400080 have been set up and the ISSO and SA at a minimum are alerted.
If there is no evidence that alerts are sent in the event of an audit processing failure, this is a finding.
M
3243