From: Steve Grubb <sgrubb@redhat.com>
To: linux-audit@redhat.com
Subject: Re: More info on remote logging
Date: Tue, 18 May 2010 10:43:24 -0400 [thread overview]
Message-ID: <201005181043.25004.sgrubb@redhat.com> (raw)
In-Reply-To: <AANLkTik_S6FT-9DzvVcLNm7sjiWD31p3xeYBh8bPUO25@mail.gmail.com>
On Tuesday 18 May 2010 10:27:32 am Konstantin Ryabitsev wrote:
> I'm interested in sending audit logs to a central logging server. One
> option is using the builtin syslog plugin for audisp, but I also see
> audisp-remote that mentions sending logs to a remote server.
> Unfortunately, I'm having trouble finding more information about that
> (such as "what kind of a remote server" and "how do you set up a
> remote server").
auditd is the remote server. Look at the auditd.conf man page starting at the
tcp_listen_port entry to see what options you have available. One thing to
note, I do not enable the kerberos support right now on any Red Hat or Fedora
release.
> Also a suggestion -- the syslog plugin for audisp doesn't specify the
> facility, so the default facility (LOG_USER) is used. Perhaps this can
> be made configurable so I could configure syslog to only send audit
> logs to remote without duplicating them in /var/log/messages (e.g. set
> facility to local9 and only send it to a remote server, not locally)?
Sure. If you want to file a RFE bugzilla, please do.
> Currently that's not possible and I end up wasting space by having
> audit logs both in /var/log/audit/audit.log and in /var/log/messages.
> Turning off af_unix is an option, but that has a significant drawback
> of complicating ausearch/aureport.
-Steve
next prev parent reply other threads:[~2010-05-18 14:43 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2010-05-18 14:27 More info on remote logging Konstantin Ryabitsev
2010-05-18 14:43 ` Steve Grubb [this message]
2010-05-18 15:05 ` Konstantin Ryabitsev
2010-05-18 15:17 ` Steve Grubb
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=201005181043.25004.sgrubb@redhat.com \
--to=sgrubb@redhat.com \
--cc=linux-audit@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.