The Infoblox system audit records must be backed up at least every seven days onto a different system or system component than the system or component being audited.
An XCCDF Rule
Description
<VulnDiscussion>Protection of log data includes assuring log data is not accidentally lost or deleted. Backing up audit records to a different system or onto separate media than the system being audited on a defined frequency helps to assure, in the event of a catastrophic system failure, the audit records will be retained. This helps to ensure a compromise of the information system being audited does not also result in a compromise of the audit records. This requirement only applies to applications that have a native backup capability for audit records. Operating system backup requirements cover applications that do not provide native backup functions.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
- ID
- SV-214162r612370_rule
- Severity
- Medium
- References
- Updated
Remediation - Manual Procedure
Navigate to Grid >> Grid Manager >> Grid Properties >> Monitoring tab.
Enable "Log to External Syslog Servers" and configure an "External Syslog Server".
Review Infoblox audit records on the remote SYSLOG server to validate operation.
When complete, click "Save & Close" to save the changes and exit the "Properties" screen.