HIDS 1006

Example log message:

server syslogd 1.4.1: restart.


This means the syslogd system has been restarted. The system servers as the main logging system for the OS. It may be periodically restarted when logs or rotated, or if its software is updated. It may also be restarted via unauthorized activity, such as if the logging system was deactivated to hide actions and then restarted later.

Logs should be audited to see if the syslog system was disabled at any point. The HIDS 1004 and HIDS 1104 events will log if the syslogd system is specifically shut down (as opposed to restarted).

