UCF STIG Viewer Logo

Queue monitoring must be configured with threshold and action.


Overview

Finding ID Version Rule ID IA Controls Severity
V-33619 Exch-2-842 SV-44039r1_rule ECSC-1 Medium
Description
Monitors are automated 'process watchers' that respond to performance changes, and can be useful in detecting outages and alerting administrators where attention is needed. Exchange has built-in monitors that enable the administrator to generate alerts if thresholds are reached, better enabling them to react in a timely fashion. This field offers choices of alerts when a 'warning' or 'critical' threshold is reached on the SMTP queue. A good rule of thumb (default) is to issue warnings when SMTP queue growth exceeds 10 minutes and critical messages when it exceeds 20 minutes, which should only exist occasionally. Frequent alerts against this counter may indicate a network or other issue (such as inbound SPAMMER traffic) that directly impacts email delivery. Notification choices include email alert to an email enabled account, for example, an email Administrator, or invoke a script to take other action, for example, to add an Event to the Microsoft Application Event Log, where external monitors might detect it.
STIG Date
Exchange 2010 Mailbox Server STIG 2014-03-11

Details

Check Text ( C-41726r1_chk )
Note: If a third party application is performing monitoring functions, the reviewer should verify the application is monitoring correctly and mark the vulnerability NA.

To review data collection sets used for monitoring enter the following command:

perfmon

Click on the Data Collection Sets icon, Click the User Defined folder, right click the data collection set. If no sets are defined or queues are not being monitored, this is a finding.
Fix Text (F-37511r1_fix)
Open the Exchange Management Console.
Expand the tree in the left column.
Click the Exchange Toolbox icon.
Configure the system to use User Defined data collection for monitoring the queues.