Skip to content

Verify User Who Owns /var/log/syslog File

An XCCDF Rule

Description

To properly set the owner of /var/log/syslog, run the command:

$ sudo chown syslog /var/log/syslog 

Rationale

The /var/log/syslog file contains logs of error messages in the system and should only be accessed by authorized personnel.

ID
xccdf_org.ssgproject.content_rule_file_owner_var_log_syslog
Severity
Medium
References
Updated



Remediation - Ansible

- name: Test for existence /var/log/syslog
  stat:
    path: /var/log/syslog
  register: file_exists
  tags:
  - DISA-STIG-UBTU-20-010421

Remediation - Shell Script

chown 104 /var/log/syslog