Skip to content
Back to skills

Cis Cassandra40 V130 4.1

ASecurity

Ensure that logging is enabled

  • 2,182 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added May 30, 2026
securitygobashnodeawssecurity

Security analysis

A100/100

Scanned May 30, 2026

npx -y skills add CyberStrikeus/CyberStrike --skill cis-cassandra40-v130-4.1 --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cis Cassandra40 V130 4.1?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cis Cassandra40 V130 4.1
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/cyberstrikeus-cis-cassandra40-v130-4-1/badge)](https://www.skillsdirectory.com/skills/cyberstrikeus-cis-cassandra40-v130-4-1)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: cis-cassandra40-v130-4.1
description: "Ensure that logging is enabled"
category: cis-cassandra
version: "1.3.0"
author: cyberstrike-official
tags: [cis, cassandra, auditing, logging]
cis_id: "4.1"
cis_benchmark: "CIS Apache Cassandra 4.0 Benchmark v1.3.0"
tech_stack: [cassandra]
cwe_ids: []
chains_with: []
prerequisites: []
severity_boost: {}
---

# 4.1 Ensure that logging is enabled

## Profile Applicability

- Level 1 - Cassandra
- Level 1 - Cassandra on Linux

## Description

Apache Cassandra uses Logback for logging functionality. While this can be set using `nodetool setlogginglevel` changes made using this method will be reverted to the level specified in the `logback.xml` file the next time the process restarts.

The configurable logging levels are:

- OFF
- TRACE
- DEBUG
- INFO (Default)
- WARN
- ERROR

## Rationale

If logging is not enabled, issues may go undiscovered, and compromises and other incidents may occur without being quickly detected. It may also not be possible to provide evidence of compliance with security laws, regulations, and other requirements.

## Audit

Execute the following command to confirm the setting is correct:

```bash
$ nodetool getlogginglevels
Logger Name                                        Log Level
ROOT                                               INFO
org.clsecurity.workbench                           WARN
```

If set to OFF then this is a finding.

## Remediation

To remediate this setting:

1. Edit the `logback-test.xml` if present; otherwise, edit the `logback.xml`

```xml
<configuration scan="true">

    <appender name="STDOUT"
    class="ch.qos.logback.core.ConsoleAppender">
        <filter class="ch.qos.logback.classic.filter.ThresholdFilter">
            <level>INFO</level>
        </filter>
        <encoder>
            <pattern>%~5level [%thread] %date{ISO8601} %F:%L -
%msg%n</pattern>
        </encoder>
    </appender>

    <root level="INFO">
        <appender-ref ref="STDOUT" />
    </root>

    <logger name="org.clsecurity.workbench" level="WARN"/>
</configuration>
```

2. Restart the Apache Cassandra

## Default Value

INFO

## References

1. http://cassandra.apache.org/doc/latest/troubleshooting/reading_logs.html?highlight=logging
2. https://logback.qos.ch/manual/configuration.html

## CIS Controls

**Controls Version v8:**

- 8.5 Collect Detailed Audit Logs
  - Configure detailed audit logging for enterprise assets containing sensitive data. Include event source, date, username, timestamp, source addresses, destination addresses, and other useful elements that could assist in a forensic investigation.

**Controls Version v7:**

- 6.3 Enable Detailed Logging
  - Enable system logging to include detailed information such as an event source, date, user, timestamp, source addresses, destination addresses, and other useful elements.

## Profile

- Level 1 | Automated

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…