Skip to content
Catalogs
XCCDF
Central Log Server Security Requirements Guide
SRG-APP-000356
The Central Log Server must be configured for centralized management of the events repository for the purposes of configuration, analysis, and reporting.
The Central Log Server must be configured for centralized management of the events repository for the purposes of configuration, analysis, and reporting. An XCCDF Rule
The Central Log Server must be configured for centralized management of the events repository for the purposes of configuration, analysis, and reporting.
Low Severity
<VulnDiscussion>If the application is not configured to centrally manage the content captured in the log records, identification, troubleshooting, and correlation of suspicious behavior would be difficult and could lead to a delayed or incomplete analysis of an ongoing attack.
The content captured in log records must be managed from a central location (necessitating automation). Centralized management of log records and logs provides for efficiency in maintenance and management of records, as well as the backup and archiving of those records. Application components requiring centralized audit log management must be configured to support centralized management.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>