The Cisco ISE must configure a remote syslog where audit records are stored on a centralized logging target that is different from the system being audited.
An XCCDF Rule
Description
Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Storing audit logs to a different system than that being audited is a common process in information systems with limited audit storage capacity.
- ID
- SV-242627r961860_rule
- Version
- CSCO-NM-000210
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Create a Remote Logging Target and direct logging to that target. To create an external logging target, complete the following steps:
1. Choose Administration >> System >> Logging >> Remote Logging Targets.
2. Click "Add".
3. Configure the following fields.
- Name - Enter the name of the new target