The SLES for vRealize must, at a minimum, off-load audit information on interconnected systems in real time and off-load standalone systems weekly.


Finding ID Version Rule ID IA Controls Severity
V-89863 VRAU-SL-001495 SV-100513r1_rule Medium
Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Off-loading is a common process in information systems with limited audit storage capacity.
VMware vRealize Automation 7.x SLES Security Technical Implementation Guide 2018-10-12


Check Text ( C-89555r1_chk )
Check the "syslog" configuration file for remote syslog servers:

# cat /etc/syslog-ng/syslog-ng.conf | grep logserver

If no line is returned, or "logserver" is commented out, this is a finding.
Fix Text (F-96605r2_fix)
Edit the syslog configuration file and add an appropriate remote syslog server:

In the /etc/syslog-ng/syslog-ng.conf file, the remote logging entries must be uncommented and the IP address must be modified to point to the remote syslog server:

# Enable this and adopt IP to send log messages to a log server.
destination logserver { udp("" port(514)); };
log { source(src); destination(logserver); };