SV-90631r1_rule
V-75943
SRG-NET-000334-ALG-000050
CACT-AG-000010
CAT II
10
Configure CounterACT to off-load audit records onto a centralized log server.
1. Connect to CounterACT’s Admin Console and log in.
2. Go to Tools >> Options >> Plugins >> Syslog.
3. Ensure a Syslog server is configured in the "Send To" tab.
4. On the Events Filtering Tab, ensure all radio buttons associated with NAC Events, Threat Protection, System Logs, User Operations, and Operating System messages are selected.
5. Select "OK". (Select "Apply" if changes were made.)
Verify CounterACT off-loads audit records onto a centralized log server.
1. Connect to CounterACT’s Admin Console and log in.
2. Go to Tools >> Options >> Plugins >> Syslog.
3. Verify a Syslog server is configured in the "Send To" tab.
4. On the Events Filtering Tab, ensure all radio buttons associated with NAC Events, Threat Protection, System Logs, User Operations, and Operating System messages are selected.
If CounterACT does not off-load audit records onto a centralized log server, this is a finding.
V-75943
False
CACT-AG-000010
Verify CounterACT off-loads audit records onto a centralized log server.
1. Connect to CounterACT’s Admin Console and log in.
2. Go to Tools >> Options >> Plugins >> Syslog.
3. Verify a Syslog server is configured in the "Send To" tab.
4. On the Events Filtering Tab, ensure all radio buttons associated with NAC Events, Threat Protection, System Logs, User Operations, and Operating System messages are selected.
If CounterACT does not off-load audit records onto a centralized log server, this is a finding.
M
3223