CIS Ubuntu 14.04 LTS - 4.2.1.1 Ensure rsyslog Service is enabled

Enable the rsyslog service to ensure system logging is active

cyberstrikeus Updated

File contents

4.2.1.1 Ensure rsyslog Service is enabled (Scored)

Profile Applicability

  • Level 1 - Server
  • Level 1 - Workstation

Description

Once the rsyslog package is installed it needs to be activated.

Rationale

If the rsyslog service is not activated the system may default to the syslogd service or lack logging instead.

Audit Procedure

Verify that the rsyslog service is active:

initctl show-config rsyslog

Expected Result

rsyslog
  start on filesystem
  stop on runlevel [06]

Remediation

Set the proper start conditions in /etc/init/rsyslog.conf:

start on filesystem

Default Value

rsyslog is typically enabled by default on Ubuntu 14.04.

References

  1. CIS Controls v6.1 - 6.2 Ensure Audit Log Settings Support Appropriate Log Entry Formatting

Profile

  • Level 1 - Server
  • Level 1 - Workstation

cyberstrikeus/cyberstrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Operating_Systems/Ubuntu/cis-ubuntu-linux-14-04-lts-benchmark-v2/cis-ubuntu1404-v210-4-2-1-1 commit d6148947d1

Frequently asked questions

npx skillmds@latest add cyberstrikeus/cis-ubuntu-14-04-lts-4-2-1-1-ensure-rsyslog-service-is-enabl