Skip to content

The Cisco ISE must configure a remote syslog where audit records are stored on a centralized logging target that is different from the system being audited.

An XCCDF Rule

Description

Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Storing audit logs to a different system than that being audited is a common process in information systems with limited audit storage capacity.

ID
SV-242627r961860_rule
Version
CSCO-NM-000210
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Create a Remote Logging Target and direct logging to that target. To create an external logging target, complete the following steps:

1. Choose Administration >> System >> Logging >> Remote Logging Targets.
2. Click "Add".
3. Configure the following fields.
- Name - Enter the name of the new target