logging_services_active: add syslog-ng as a recognized logging service#14777
logging_services_active: add syslog-ng as a recognized logging service#14777israel-villar wants to merge 1 commit into
Conversation
The OVAL check and description only listed rsyslog and systemd-journald. Add syslog-ng to the unit pattern so the rule passes on systems that use syslog-ng as their primary logging daemon (e.g. Debian 13 CIS profile). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
|
Hi @israel-villar. Thanks for your PR. I'm waiting for a ComplianceAsCode member to verify that this patch is reasonable to test. If it is, they should reply with Regular contributors should join the org to skip this step. Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
This datastream diff is auto generated by the check Click here to see the full diffNew content has different text for rule 'xccdf_org.ssgproject.content_rule_logging_services_active'.
--- xccdf_org.ssgproject.content_rule_logging_services_active
+++ xccdf_org.ssgproject.content_rule_logging_services_active
@@ -5,7 +5,7 @@
[description]:
Ensure that a logging system is active and in use.
-systemctl is-active rsyslog systemd-journald
+systemctl is-active rsyslog syslog-ng systemd-journald
The command should return at least one active.
|
The OVAL check and description only listed rsyslog and systemd-journald. Add syslog-ng to the unit pattern so the rule passes on systems that use syslog-ng as their primary logging daemon (e.g. Debian 13 CIS profile).
Description:
Add
syslog-ngto the systemd unit pattern in thelogging_services_activeOVAL check and to the example command in the rule description.
Previously the rule only recognized
rsyslogandsystemd-journaldasvalid active logging services. Systems that use syslog-ng as their primary
logging daemon (e.g. Debian 13 with the CIS profile) would fail this check
even when a logging service is correctly active.
Rationale:
"at least one logging service is active", so syslog-ng should be included
alongside rsyslog and systemd-journald.
Review Hints: