linux-audit.redhat.com archive mirror
 help / color / mirror / Atom feed
* More info on remote logging
@ 2010-05-18 14:27 Konstantin Ryabitsev
  2010-05-18 14:43 ` Steve Grubb
  0 siblings, 1 reply; 4+ messages in thread
From: Konstantin Ryabitsev @ 2010-05-18 14:27 UTC (permalink / raw)
  To: Linux-audit

Hi, all:

I'm interested in sending audit logs to a central logging server. One
option is using the builtin syslog plugin for audisp, but I also see
audisp-remote that mentions sending logs to a remote server.
Unfortunately, I'm having trouble finding more information about that
(such as "what kind of a remote server" and "how do you set up a
remote server").

Also a suggestion -- the syslog plugin for audisp doesn't specify the
facility, so the default facility (LOG_USER) is used. Perhaps this can
be made configurable so I could configure syslog to only send audit
logs to remote without duplicating them in /var/log/messages (e.g. set
facility to local9 and only send it to a remote server, not locally)?
Currently that's not possible and I end up wasting space by having
audit logs both in /var/log/audit/audit.log and in /var/log/messages.
Turning off af_unix is an option, but that has a significant drawback
of complicating ausearch/aureport.

Regards,
-- 
McGill University IT Security
Konstantin "Kay" Ryabitsev
Montréal, Québec

--
Linux-audit mailing list
Linux-audit@redhat.com
https://www.redhat.com/mailman/listinfo/linux-audit

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: More info on remote logging
  2010-05-18 14:27 More info on remote logging Konstantin Ryabitsev
@ 2010-05-18 14:43 ` Steve Grubb
  2010-05-18 15:05   ` Konstantin Ryabitsev
  0 siblings, 1 reply; 4+ messages in thread
From: Steve Grubb @ 2010-05-18 14:43 UTC (permalink / raw)
  To: linux-audit

On Tuesday 18 May 2010 10:27:32 am Konstantin Ryabitsev wrote:
> I'm interested in sending audit logs to a central logging server. One
> option is using the builtin syslog plugin for audisp, but I also see
> audisp-remote that mentions sending logs to a remote server.
> Unfortunately, I'm having trouble finding more information about that
> (such as "what kind of a remote server" and "how do you set up a
> remote server").

auditd is the remote server. Look at the auditd.conf man page starting at the 
tcp_listen_port entry to see what options you have available. One thing to 
note, I do not enable the kerberos support right now on any Red Hat or Fedora 
release.

 
> Also a suggestion -- the syslog plugin for audisp doesn't specify the
> facility, so the default facility (LOG_USER) is used. Perhaps this can
> be made configurable so I could configure syslog to only send audit
> logs to remote without duplicating them in /var/log/messages (e.g. set
> facility to local9 and only send it to a remote server, not locally)?

Sure. If you want to file a RFE bugzilla, please do.

> Currently that's not possible and I end up wasting space by having
> audit logs both in /var/log/audit/audit.log and in /var/log/messages.
> Turning off af_unix is an option, but that has a significant drawback
> of complicating ausearch/aureport.

-Steve

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: More info on remote logging
  2010-05-18 14:43 ` Steve Grubb
@ 2010-05-18 15:05   ` Konstantin Ryabitsev
  2010-05-18 15:17     ` Steve Grubb
  0 siblings, 1 reply; 4+ messages in thread
From: Konstantin Ryabitsev @ 2010-05-18 15:05 UTC (permalink / raw)
  To: linux-audit

On Tue, May 18, 2010 at 10:43 AM, Steve Grubb <sgrubb@redhat.com> wrote:
> On Tuesday 18 May 2010 10:27:32 am Konstantin Ryabitsev wrote:
>> I'm interested in sending audit logs to a central logging server. One
>> option is using the builtin syslog plugin for audisp, but I also see
>> audisp-remote that mentions sending logs to a remote server.
>> Unfortunately, I'm having trouble finding more information about that
>> (such as "what kind of a remote server" and "how do you set up a
>> remote server").
>
> auditd is the remote server. Look at the auditd.conf man page starting at the
> tcp_listen_port entry to see what options you have available. One thing to
> note, I do not enable the kerberos support right now on any Red Hat or Fedora
> release.

Ah, okay -- I suspected as such but wanted to make sure. Is there a
way to send audit data encrypted if kerberos is not enabled?

>> Also a suggestion -- the syslog plugin for audisp doesn't specify the
>> facility, so the default facility (LOG_USER) is used. Perhaps this can
>> be made configurable so I could configure syslog to only send audit
>> logs to remote without duplicating them in /var/log/messages (e.g. set
>> facility to local9 and only send it to a remote server, not locally)?
>
> Sure. If you want to file a RFE bugzilla, please do.

Created as
https://bugzilla.redhat.com/show_bug.cgi?id=593340

Thanks!
-- 
McGill University IT Security
Konstantin "Kay" Ryabitsev
Montréal, Québec

--
Linux-audit mailing list
Linux-audit@redhat.com
https://www.redhat.com/mailman/listinfo/linux-audit

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: More info on remote logging
  2010-05-18 15:05   ` Konstantin Ryabitsev
@ 2010-05-18 15:17     ` Steve Grubb
  0 siblings, 0 replies; 4+ messages in thread
From: Steve Grubb @ 2010-05-18 15:17 UTC (permalink / raw)
  To: linux-audit

On Tuesday 18 May 2010 11:05:55 am Konstantin Ryabitsev wrote:
> On Tue, May 18, 2010 at 10:43 AM, Steve Grubb <sgrubb@redhat.com> wrote:
> > On Tuesday 18 May 2010 10:27:32 am Konstantin Ryabitsev wrote:
> >> I'm interested in sending audit logs to a central logging server. One
> >> option is using the builtin syslog plugin for audisp, but I also see
> >> audisp-remote that mentions sending logs to a remote server.
> >> Unfortunately, I'm having trouble finding more information about that
> >> (such as "what kind of a remote server" and "how do you set up a
> >> remote server").
> > 
> > auditd is the remote server. Look at the auditd.conf man page starting at
> > the tcp_listen_port entry to see what options you have available. One
> > thing to note, I do not enable the kerberos support right now on any Red
> > Hat or Fedora release.
> 
> Ah, okay -- I suspected as such but wanted to make sure. Is there a
> way to send audit data encrypted if kerberos is not enabled?

Not by auditd and audisp-remote. There may be ways of creating an encrypted 
tunnel between the systems if need be. 

Also note that the remote logging capability is listed as "In Tech Preview" 
status if RHEL is involved. There are a few odds and ends that need some 
development work, such as a "store and forward" mode so that the audit system 
is lossless. Right now, the audit events in transit to a remote system only 
exist in memory and if the system oopses, all events in memory are lost.


> > Sure. If you want to file a RFE bugzilla, please do.
> 
> Created as
> https://bugzilla.redhat.com/show_bug.cgi?id=593340

Thanks.

-Steve

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2010-05-18 15:17 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-05-18 14:27 More info on remote logging Konstantin Ryabitsev
2010-05-18 14:43 ` Steve Grubb
2010-05-18 15:05   ` Konstantin Ryabitsev
2010-05-18 15:17     ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).