| name | cis-nginx-v300-3-3 |
| description | Ensure error logging is enabled and set to the info logging level (Manual) |
| category | cis-nginx |
| version | 3.0 |
| author | cyberstrike-official |
| tags | ["cis","nginx","web-server","reverse-proxy","logging"] |
| cis_id | 3.3 |
| cis_benchmark | CIS NGINX Benchmark v3.0.0 |
| tech_stack | ["nginx","linux","web-server"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
CIS 3.3 — Ensure error logging is enabled and set to the info logging level
Profile Applicability
- Level 1 - Webserver
- Level 1 - Proxy
- Level 1 - Loadbalancer
Description
The error_log directive configures logging for server errors and operational messages. Unlike access logs, error logs capture diagnostic information about failed requests, upstream connection issues, and configuration errors. The log level determines the verbosity of these messages and should be set to capture sufficient detail (typically notice or info) without overwhelming the storage system.
Rationale
While access logs capture incoming request patterns, error logs provide the internal system context required to diagnose why a request failed. They are essential for identifying:
- Upstream Failures: Connection timeouts or refused connections to backend servers (e.g., application server is down).
- Process Anomalies: Unexpected worker process terminations or restarts, which may indicate resource exhaustion or exploitation attempts.
- Configuration Errors: Invalid request handling that NGINX rejects before logging to access logs (e.g., header size limits exceeded).
Without error logs, an administrator sees a "500 Internal Server Error" in the access log but has no way to determine the root cause.
Impact
Setting the log level to info (or even debug) can generate a significant volume of log data, especially on busy servers or during denial-of-service attacks. This increases disk I/O and storage requirements. Ensure that log rotation (e.g., via logrotate) is configured and storage usage is monitored to prevent disk exhaustion.
Audit Procedure
1. Verify Configuration:
Check the fully loaded configuration for error log settings:
nginx -T 2>/dev/null | grep -i "error_log"
Evaluation:
- Presence: Verify that
error_log is defined globally in the main context (or http block).
- Destination: Ensure it points to a valid local file (e.g.,
/var/log/nginx/error.log) accessible for ingestion by log shippers.
- Level: Confirm the level is set according to your internal "Monitoring and Logging" policy.