[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-97982-3

Platform: cpe:/o:microsoft:windows_server_2022:::x64Date: (C)2022-06-07   (M)2023-07-04



This policy setting controls Event Log behavior when the log file reaches its maximum size and takes effect only if the "Retain old events" policy setting is enabled. If you enable this policy setting and the "Retain old events" policy setting is enabled, the Event Log file is automatically closed and renamed when it is full. A new file is then started. If you disable this policy setting and the "Retain old events" policy setting is enabled, new events are discarded and old events are retained. If you do not configure this policy setting and the "Retain old events" policy setting is enabled, new events are discarded and the old events are retained. Fix: (1) GPO: Computer ConfigurationAdministrative TemplatesWindows ComponentsEvent Log ServiceApplicationBack up log automatically when full (2) REG: HKEY_LOCAL_MACHINESoftwarePoliciesMicrosoftWindowsEventLogApplication!AutoBackupLogFiles


Parameter:

[enabled/disabled]


Technical Mechanism:

(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Event Log Service\Application\Back up log automatically when full (2) REG: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\EventLog\Application!AutoBackupLogFiles

CCSS Severity:CCSS Metrics:
CCSS Score : 4.7Attack Vector: LOCAL
Exploit Score: 1.0Attack Complexity: HIGH
Impact Score: 3.6Privileges Required: LOW
Severity: MEDIUMUser Interaction: NONE
Vector: AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HScope: UNCHANGED
 Confidentiality: NONE
 Integrity: NONE
 Availability: HIGH
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:81267


OVAL    1
oval:org.secpod.oval:def:81267
XCCDF    1
xccdf_org.secpod_benchmark_general_Windows_Server_2022

© SecPod Technologies