# Cis Docker V170 2.3

> Ensure the logging level is set to 'info'

- Skill: `cyberstrikeus/cis-docker-v170-2-3` (Agent Skill)
- Install (CLI): `npx skillmds@latest add cyberstrikeus/cis-docker-v170-2-3`
- Raw SKILL.md: https://api.skillmd.com/api/skills/cyberstrikeus/cis-docker-v170-2-3/raw
- Safety review: PASS (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: DevOps & Infra
- Author: cyberstrikeus (https://skillmd.com/u/cyberstrikeus)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/cyberstrikeus/cis-docker-v170-2-3

---


# CIS Docker Benchmark v1.7.0 - Control 2.3

## Profile Applicability

- **Level:** 1 - Docker - Linux

## Description

Set Docker daemon log level to `info`.

## Rationale

Setting up an appropriate log level, configures the Docker daemon to log events that you would want to review later. A base log level of `info` and above would capture all logs except debug logs. Until and unless required, you should not run Docker daemon at `debug` log level.

## Impact

None.

## Audit Procedure

To confirm this setting a combination of reviewing the dockerd start-up options and a review of any settings in `/etc/docker/daemon.json` should be completed.

To review the dockerd startup options, use:

```bash
ps -ef | grep dockerd
```

Ensure that either the `--log-level` parameter is not present or if present, then it is set to `info`.

The contents of `/etc/docker/daemon.json` should also be reviewed for this setting.

## Remediation

Ensure that the Docker daemon configuration file has the following configuration included:

```json
"log-level": "info"
```

Alternatively, run the Docker daemon as below:

```bash
dockerd --log-level="info"
```

## Default Value

By default, Docker daemon is set to log level of `info`.

## References

1. https://docs.docker.com/engine/reference/commandline/dockerd/

## CIS Controls

| Controls Version | Control                                                                                                                                                                                                                                                                                  | IG 1 | IG 2 | IG 3 |
| ---------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---- | ---- | ---- |
| v8               | 8.5 Collect Detailed Audit Logs<br/>Configure detailed audit logging for enterprise assets containing sensitive data. Include event source, date, username, timestamp, source addresses, destination addresses, and other useful elements that could assist in a forensic investigation. |      | ●    | ●    |
| v7               | 6.2 Activate audit logging<br/>Ensure that local logging has been enabled on all systems and networking devices.                                                                                                                                                                         | ●    | ●    | ●    |
| v7               | 6.3 Enable Detailed Logging<br/>Enable system logging to include detailed information such as an event source, date, user, timestamp, source addresses, destination addresses, and other useful elements.                                                                                |      | ●    | ●    |

## Profile

**Level 1 - Docker - Linux** (Manual)

