Vulnerability Discussion
The use of separate file systems for different paths can protect the system from failures resulting from a file system becoming full or failing.
Check
Verify that a separate file system has been created for "/var/log".
Check that a file system has been created for "/var/log" with the following command:
$ sudo grep /var/log /etc/fstab
/dev/mapper/... /var/log xfs defaults,nodev,noexec,nosuid 0 0
If a separate entry for "/var/log" is not in use, this is a finding.
Fix
Migrate the "/var/log" path onto a separate file system.