SV-95825r1_rule
V-81111
SRG-APP-000086-AU-000390
SRG-APP-000086-AU-000390
CAT II
10
Where multiple log servers are installed in the enclave, configure each log server to forward logs to a consolidated aggregation server.
Examine the network architecture and documentation.
If the log server being reviewed is one of multiple log servers in the enclave or on a network segment, verify that an aggregation server exists and that the log server under review is configured to send records received from the host and devices to the aggregation server or centralized SIEM/events sever.
Where multiple log servers are installed in the enclave, if each log server is not configured to send log records to a central aggregation server or other consolidated events repository, this is a finding.
V-81111
False
SRG-APP-000086-AU-000390
Examine the network architecture and documentation.
If the log server being reviewed is one of multiple log servers in the enclave or on a network segment, verify that an aggregation server exists and that the log server under review is configured to send records received from the host and devices to the aggregation server or centralized SIEM/events sever.
Where multiple log servers are installed in the enclave, if each log server is not configured to send log records to a central aggregation server or other consolidated events repository, this is a finding.
M
3395