All of lore.kernel.org
 help / color / mirror / Atom feed
From: LC Bruzenak <lenny@magitekltd.com>
To: linux-audit@redhat.com
Subject: Re: Remote logging with autitd
Date: Sun, 02 Nov 2014 15:25:50 -0600	[thread overview]
Message-ID: <5456A15E.2060000@magitekltd.com> (raw)
In-Reply-To: <DUB131-W69BAA3BCB6D84E8B977699DD980@phx.gbl>


[-- Attachment #1.1.1: Type: text/plain, Size: 1248 bytes --]

On 11/02/2014 03:16 PM, Wouter van Verre wrote:
> Hi Steve,
>
> Many thanks for your response.
> I will be reading the presentation and the examples in the tarball and
> go from there for implementing my processing plugin.
>
> Regarding the logging to disk on the central server:
> I have node names set up for both servers now and am now getting the
> following behaviour:
>    On the client server I can see the events being prefixed with
> node=Elephant in the log on that server.
>    On the central server I can see that local events are being
> prefixed with node=Mongoose.
>    However, events that were sent to the central server by the client
> server show up in the central server's log with
>    node=localhost.localdomain. So it seems that the node information
> gets lost between the client and central server?
>
> Would you have any idea why the node information is lost?
>
>
> Many thanks,
>
> Wouter

Check /etc/audisp/audispd.conf on your client.
Look at the  line with "name_format=" and it probably says "hostname"
(case insensitive).
Test this by checking "% hostname" command on your client.
See the audispd.conf man page for more info.

LCB

-- 
LC (Lenny) Bruzenak
lenny@magitekltd.com


[-- Attachment #1.1.2: Type: text/html, Size: 2163 bytes --]

[-- Attachment #1.2: S/MIME Cryptographic Signature --]
[-- Type: application/pkcs7-signature, Size: 2193 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



  reply	other threads:[~2014-11-02 21:25 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-11-01 21:49 Remote logging with autitd Wouter van Verre
2014-11-02 18:12 ` Steve Grubb
2014-11-02 21:16   ` Wouter van Verre
2014-11-02 21:25     ` LC Bruzenak [this message]
2014-11-02 22:09       ` Wouter van Verre
2014-11-13 22:23     ` Wouter van Verre
2014-11-14  2:44       ` Steve Grubb
2014-11-14 15:16         ` AUID question David Flatley
2014-11-14 15:26           ` Steve Grubb
2014-11-18 12:21         ` Remote logging with autitd Wouter van Verre

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=5456A15E.2060000@magitekltd.com \
    --to=lenny@magitekltd.com \
    --cc=linux-audit@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.