linux-audit.redhat.com archive mirror
 help / color / mirror / Atom feed
* Audisp-remote - connection refused.
@ 2017-10-02 18:55 Rituraj Buddhisagar
  2017-10-02 19:51 ` Rituraj Buddhisagar
  2017-10-02 21:58 ` Steve Grubb
  0 siblings, 2 replies; 16+ messages in thread
From: Rituraj Buddhisagar @ 2017-10-02 18:55 UTC (permalink / raw)
  To: Steve Grubb, linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 1137 bytes --]

Hi

I tried my best to configure the audisp-remote.
I am getting below error on the client machine in /var/log/syslog.

Oct  2 14:41:15 xxxxxx audisp-remote: Error connecting to 192.168.103.7:
Connection refused


192.168.103.7 is the IP address of the central log server.

Notes: My settings are below:

on server as well on client:
/etc/audisp/audisp-remote

remote_server = 192.168.103.7
port = 6999
local_port = 6999
transport = tcp
queue_file = /var/spool/audit/remote.log
mode = immediate
queue_depth = 2048
format = ascii
network_retry_time = 100


I have enabled name_format=HOSTNAME only in one place (in
/etc/audisp/audispd.conf - and not in /etc/audit/auditd.conf

entries in auditd.conf:

rtcp_listen_port = 6999
tcp_listen_queue = 5
tcp_max_per_addr = 10
tcp_client_ports = 0-65535
tcp_client_max_idle = 0


I see the server is listening on the port 6999 as below but its not
accepting client request.
root@logs:/etc# lsof -i :6999
COMMAND    PID USER   FD   TYPE DEVICE SIZE/OFF NODE NAME
audisp-re 9091 root    3u  IPv4  33671      0t0  TCP 192.168.103.7:6999->
192.168.103.7:6999 (ESTABLISHED)



Best Regards,
Rituraj B

[-- Attachment #1.2: Type: text/html, Size: 5536 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 16+ messages in thread

end of thread, other threads:[~2017-10-04 16:28 UTC | newest]

Thread overview: 16+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-10-02 18:55 Audisp-remote - connection refused Rituraj Buddhisagar
2017-10-02 19:51 ` Rituraj Buddhisagar
2017-10-02 21:58 ` Steve Grubb
2017-10-03  3:31   ` Rituraj Buddhisagar
2017-10-03 12:44     ` Steve Grubb
2017-10-03 12:52       ` Rituraj Buddhisagar
2017-10-03 12:58         ` Rituraj Buddhisagar
2017-10-03 15:08         ` Steve Grubb
2017-10-03 18:40           ` Rituraj Buddhisagar
2017-10-03 19:08             ` Rituraj Buddhisagar
2017-10-03 20:00               ` Rituraj Buddhisagar
2017-10-03 20:22                 ` Steve Grubb
2017-10-04 14:01                   ` Rituraj Buddhisagar
2017-10-04 15:19                     ` Steve Grubb
2017-10-04 16:02                       ` Rituraj Buddhisagar
2017-10-04 16:28                         ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).