The Central Log Server must implement the capability to centrally review and analyze audit records from multiple components within the system.


Overview

Finding ID Version Rule ID IA Controls Severity
V-263558 SRG-APP-000745-AU-000120 SV-263558r982403_rule Medium
Description
Automated mechanisms for centralized reviews and analyses include security information and event management products.
STIG Date
Central Log Server Security Requirements Guide 2024-07-02

Details

Check Text ( C-67458r982402_chk )
Verify the Central Log Server is configured to implement the capability to centrally review and analyze audit records from multiple components within the system.

If the Central Log Server is not configured to implement the capability to centrally review and analyze audit records from multiple components within the system, this is a finding.
Fix Text (F-67366r981758_fix)
Configure the Central Log Server to implement the capability to centrally review and analyze audit records from multiple components within the system.