From: Steve Grubb <sgrubb@redhat.com>
To: linux-audit@redhat.com
Subject: Re: More info on remote logging
Date: Tue, 18 May 2010 11:17:14 -0400 [thread overview]
Message-ID: <201005181117.14815.sgrubb@redhat.com> (raw)
In-Reply-To: <AANLkTilsztO6fO3y4VFz0IQ7T4n6f4vmkIuyoj4vHPQl@mail.gmail.com>
On Tuesday 18 May 2010 11:05:55 am Konstantin Ryabitsev wrote:
> On Tue, May 18, 2010 at 10:43 AM, Steve Grubb <sgrubb@redhat.com> wrote:
> > On Tuesday 18 May 2010 10:27:32 am Konstantin Ryabitsev wrote:
> >> I'm interested in sending audit logs to a central logging server. One
> >> option is using the builtin syslog plugin for audisp, but I also see
> >> audisp-remote that mentions sending logs to a remote server.
> >> Unfortunately, I'm having trouble finding more information about that
> >> (such as "what kind of a remote server" and "how do you set up a
> >> remote server").
> >
> > auditd is the remote server. Look at the auditd.conf man page starting at
> > the tcp_listen_port entry to see what options you have available. One
> > thing to note, I do not enable the kerberos support right now on any Red
> > Hat or Fedora release.
>
> Ah, okay -- I suspected as such but wanted to make sure. Is there a
> way to send audit data encrypted if kerberos is not enabled?
Not by auditd and audisp-remote. There may be ways of creating an encrypted
tunnel between the systems if need be.
Also note that the remote logging capability is listed as "In Tech Preview"
status if RHEL is involved. There are a few odds and ends that need some
development work, such as a "store and forward" mode so that the audit system
is lossless. Right now, the audit events in transit to a remote system only
exist in memory and if the system oopses, all events in memory are lost.
> > Sure. If you want to file a RFE bugzilla, please do.
>
> Created as
> https://bugzilla.redhat.com/show_bug.cgi?id=593340
Thanks.
-Steve
prev parent reply other threads:[~2010-05-18 15:17 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2010-05-18 14:27 More info on remote logging Konstantin Ryabitsev
2010-05-18 14:43 ` Steve Grubb
2010-05-18 15:05 ` Konstantin Ryabitsev
2010-05-18 15:17 ` Steve Grubb [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=201005181117.14815.sgrubb@redhat.com \
--to=sgrubb@redhat.com \
--cc=linux-audit@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).