STIGUI
V-259185CAT II Medium severitySV-259185r1210431_rule

The vCenter PostgreSQL service must off-load audit data to a separate log management facility.

Rule version VCPG-80-000122 · STIG v2 · 2026-06-02

Discussion

Information stored in one location is vulnerable to accidental or incidental deletion or alteration.

Off-loading is a common process in information systems with limited audit storage capacity.

The database management system (DBMS) may write audit records to database tables, to files in the file system, to other kinds of local repository, or directly to a centralized log management system. Whatever the method used, it must be compatible with off-loading the records to the centralized system.

Check

By default, a vmware-services-vmware-vpostgres.conf rsyslog and vmware-services-vmware-postgres-archiver.conf configuration file include the service logs when syslog is configured on vCenter, but they must be verified.

At the command prompt, run the following command:

# cat /etc/vmware-syslog/vmware-services-vmware-vpostgres.conf

Expected result:

# vmware-vpostgres first logs stdout, before loading configuration input(type="imfile" File="/var/log/vmware/vpostgres/serverlog.stdout" Tag="vpostgres-first" Severity="info" Facility="local0" deleteStateOnFileDelete="on" reopenOnTruncate="on") # vmware-vpostgres first logs stderr, before loading configuration input(type="imfile" File="/var/log/vmware/vpostgres/serverlog.stderr" Tag="vpostgres-first" Severity="info" Facility="local0" deleteStateOnFileDelete="on" reopenOnTruncate="on") # vmware-vpostgres logs input(type="imfile" File="/var/log/vmware/vpostgres/postgresql-*.log" Tag="vpostgres" Severity="info" Facility="local0" deleteStateOnFileDelete="on" reopenOnTruncate="on")

Note: If the entries for "deleteStateOnFileDelete" and "reopenOnTruncate" do not exist, this is not a finding.

If the output does not match the expected result, this is a finding.

At the command prompt, run the following command:

# cat /etc/vmware-syslog/vmware-services-vmware-postgres-archiver.conf

Expected result:

# vmware-postgres-archiver stdout log input(type="imfile" File="/var/log/vmware/vpostgres/pg_archiver.log.stdout" Tag="postgres-archiver" Severity="info" Facility="local0" deleteStateOnFileDelete="on" reopenOnTruncate="on") # vmware-postgres-archiver stderr log input(type="imfile" File="/var/log/vmware/vpostgres/pg_archiver.log.stderr" Tag="postgres-archiver" Severity="info" Facility="local0" deleteStateOnFileDelete="on" reopenOnTruncate="on")

Note: If the entries for "deleteStateOnFileDelete" and "reopenOnTruncate" do not exist, this is not a finding.

If the output does not match the expected result, this is a finding.

Fix

Navigate to and open:

/etc/vmware-syslog/vmware-services-vmware-vpostgres.conf

Create the file if it does not exist.

Set the contents of the file as follows:

# vmware-vpostgres first logs stdout, before loading configuration input(type="imfile" File="/var/log/vmware/vpostgres/serverlog.stdout" Tag="vpostgres-first" Severity="info" Facility="local0" deleteStateOnFileDelete="on" reopenOnTruncate="on") # vmware-vpostgres first logs stderr, before loading configuration input(type="imfile" File="/var/log/vmware/vpostgres/serverlog.stderr" Tag="vpostgres-first" Severity="info" Facility="local0" deleteStateOnFileDelete="on" reopenOnTruncate="on") # vmware-vpostgres logs input(type="imfile" File="/var/log/vmware/vpostgres/postgresql-*.log" Tag="vpostgres" Severity="info" Facility="local0" deleteStateOnFileDelete="on" reopenOnTruncate="on")

Navigate to and open:

/etc/vmware-syslog/vmware-services-vmware-postgres-archiver.conf

Create the file if it does not exist.

Set the contents of the file as follows:

# vmware-postgres-archiver stdout log input(type="imfile" File="/var/log/vmware/vpostgres/pg_archiver.log.stdout" Tag="postgres-archiver" Severity="info" Facility="local0" deleteStateOnFileDelete="on" reopenOnTruncate="on") # vmware-postgres-archiver stderr log input(type="imfile" File="/var/log/vmware/vpostgres/pg_archiver.log.stderr" Tag="postgres-archiver" Severity="info" Facility="local0" deleteStateOnFileDelete="on" reopenOnTruncate="on")

Identifiers

Group ID
V-259185
Group title
SRG-APP-000515-DB-000318
Rule ID
SV-259185r1210431_rule
Check ID
C-62925r1210429_chk
Fix ID
F-62834r1210430_fix