Skip to content

The F5 BIG-IP appliance must generate audit records and send records to redundant central syslog servers that are separate from the appliance.

An XCCDF Rule

Description

Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. MCP audit records are generated from various components within the network device. For example, it logs the creation of DNS objects and DNSSEC configuration, including key creations. Satisfies: SRG-APP-000515-NDM-000325, SRG-APP-000360-NDM-000295, SRG-APP-000516-NDM-000350

ID
SV-266075r1024607_rule
Version
F5BI-DM-300034
Severity
High
References
Updated

Remediation Templates

A Manual Procedure

Configure two or more central syslog servers.

From the BIG-IP GUI:
1. System.
2. Logs.
3. Configuration.