1. Home
  2. Security Hardening
  3. DISA RedHat JBoss EAP 6.3 STIG V2R2
  4. JBOS-AS-000120 – JBoss must be configured to produce log records that establish which hosted application triggered the events.

JBOS-AS-000120 – JBoss must be configured to produce log records that establish which hosted application triggered the events.

Details

Application server logging capability is critical for accurate forensic analysis. Without sufficient and accurate information, a correct replay of the events cannot be determined.

By default, no web logging is enabled in JBoss. Logging can be configured per web application or by virtual server. If web application logging is not set up, application activity will not be logged.

Ascertaining the correct location or process within the application server where the events occurred is important during forensic analysis. To determine where an event occurred, the log data must contain data containing the application identity.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure log formatter to audit application activity so individual application activity can be identified.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Audit and Accountability.This control applies to the following type of system Unix.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles