STIGUI
V-285653CAT I — High severitySV-285653r1274313_rule

The Content Analysis System (CAS) must be configured to send log data to a central log server for the purpose of forwarding alerts to the administrators and the information system security officer (ISSO).

Rule version BCAS-ND-001930 · STIG v1 · 2026-09-16

Discussion

The aggregation of log data kept on a syslog server can be used to detect attacks and trigger an alert to the appropriate security personnel. The stored log data can be used to detect weaknesses in security that enable the network IA team to find and address these weaknesses before breaches can occur. Reviewing these logs, whether before or after a security breach, are important in showing whether someone is an internal employee or an outside threat.

Satisfies: SRG-APP-000516-NDM-000350, SRG-APP-000357-NDM-000293, SRG-APP-000515-NDM-000325

Check

Verify a syslog server is configured with the following steps:

1. Log on to the SSH CLI with an administrative account. 2. Enter "show running-config alerts". 3. Review the output for a configured syslog server under the "syslog-alerts" section.

If there is no configured syslog server, or if the server is not using a secure protocol (e.g., TLS), this is a finding.

Fix

Configure a syslog server with the following steps:

1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and enter the password. 3. Enter "configure terminal". Note: Ensure a DNS resolver is configured to allow for FQDN verification of the syslog server certificate. 4. Configure the DNS name server by entering "dns name-server [IP ADDRESS]". (Replace [IP ADDRESS] with the address of your DNS server.) 5. Import the CA certificate for the syslog server by entering "ssl inline fips ca-certificate [NAME OF CA] content". (Replace [NAME OF CA] with a descriptive label for the certificate.) 6. Paste the certificate content and press "CTRL + D" to save. Repeat this for each certificate in the chain. 7. Add the remote syslog server by entering "alerts syslog-alerts servers [HOSTNAME] facility default port 6514 protocol TLS". (Replace [HOSTNAME] with the fully-qualified domain name of the syslog server.) 8. Ensure all audit logs are included in the output by entering "logging include-audit-info true". 9. Enter "exit" to return to the config context, and then enter "exit" again to leave configuration mode.

Identifiers

Group ID
V-285653
Group title
SRG-APP-000516-NDM-000350
Rule ID
SV-285653r1274313_rule
Check ID
C-90333r1273076_chk
Fix ID
F-90238r1274312_fix