Rule ID
SV-258901r933764_rule
Version
V1R1
CCIs
CCI-000366
Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Off-loading is a common process in information systems with limited audit storage capacity.
If another package is used to offload logs, such as syslog-ng, and is properly configured, this is not applicable. At the command line, run the following command to verify rsyslog is enabled and running: # systemctl status rsyslog If the rsyslog service is not enabled and running, this is a finding.
At the command line, run the following commands: # systemctl enable rsyslog # systemctl start rsyslog