SV-95155r1_rule
V-80451
SRG-APP-000356
BROM-00-000765
CAT II
10
Automatically forward all contents of "history.log" to the site's central log server in real time.
Install the file monitoring agent that is provided by the site's centralized events server (e.g., syslog, SIEM) and configure to monitor and forward "history.log" (example: C:\Program Data\Bromium\BMS\Logs\history.log). Follow the instructions included with the central log server.
Ask the site representatives if they have developed and implemented a solution for storing the contents of "history.log".
Check that the backup solution has been configured to include the "history.log" files residing on the BEC.
If the BEC does not send "history.log" records to a central log server (i.e., syslog server), this is a finding.
V-80451
False
BROM-00-000765
Ask the site representatives if they have developed and implemented a solution for storing the contents of "history.log".
Check that the backup solution has been configured to include the "history.log" files residing on the BEC.
If the BEC does not send "history.log" records to a central log server (i.e., syslog server), this is a finding.
M
3375