public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
From: Steve Grubb <sgrubb@redhat.com>
To: Rituraj Buddhisagar <rituraj@vayana.com>
Cc: linux-audit@redhat.com
Subject: Re: Audisp-remote - connection refused.
Date: Wed, 04 Oct 2017 11:19:40 -0400	[thread overview]
Message-ID: <7773077.6JsVQVb1J2@x2> (raw)
In-Reply-To: <CAPHnQ1AYsmuDXitNGwPPgpGZiOTuH5MKRe8REoCCbi-BgdDdxg@mail.gmail.com>

On Wednesday, October 4, 2017 10:01:49 AM EDT Rituraj Buddhisagar wrote:
> Hi Steve / List
> 
> Now, I have built auditd from source as per the mail thread and then also
> created a startup script.
> 
> The auditd is starting successfully.
> 
> The client is able to connect to the aggregating server.
> 
> 
> *node=guslogs type=DAEMON_ACCEPT msg=audit(1507125123.240:7272):
> addr=192.168.103.2 port=60 res=success*
> 
> 
> I have made the necessary change in the server in /etc/audit/auditd.conf
> 
> *log_format = NOLOG*

This is a deprecated option tells it to not write anything to disk.

> I do not see any logs being populated - I checked log file on client, the
> server - also the /var/spool/audit/remote.log on the client.
> On the server side /var/spool/audit/remote.log is empty (I am not sure if
> this is something I should be checking at all)
> 
> I am clueless as to what is happening. Is there some way to debug this?

Did you modify auditd.conf to have the format be nolog? If so, its an 
explained condition. Nolog means no logging to disk.

> Where are these logs getting lost?
> When change the log_format back to RAW I do see the logs getting created on
> the client.

For remote logging, you should set the format to enriched. This resolves 
things locally so that the aggregating server can make sense of it later. If 
you do not want events written to disk on the remote system, set write_logs = 
no. You should also set name_format = hostname (or something else) in 
auditd.conf of the remote systems. This is so you can tell who is creating the 
events in the aggregating server.

On the aggregating server, also set the format to enriched. But there you have 
to have write_logs = yes. Also set name_format = hostname in auditd.conf of 
the server.

I would not recommend setting the name in audispd.conf for any system.

-Steve

> I did my best reading on net and debugging this - but no success. Please
> help.
> 
> On Wed, Oct 4, 2017 at 1:52 AM, Steve Grubb <sgrubb@redhat.com> wrote:
> > On Tuesday, October 3, 2017 4:00:27 PM EDT Rituraj Buddhisagar wrote:
> > > Steve,
> > > 
> > > Here is the relevant discussion on disabling the tcp listener on Ubuntu.
> > > https://www.redhat.com/archives/linux-audit/2012-September/msg00027.html
> > > 
> > > I do not know what exactly caused change - but now I think it should be
> > > enabled in distributions.
> > > 
> > > Please let me know.
> > > 
> > > Btw, I got auditd running (by setting LD_LIBRARY_PATH variable) from
> > 
> > source
> > 
> > > now. Still audispd is not started now - what is the way / sequence to
> > 
> > start
> > 
> > > auditd and audispd - if you can point me to some reference or a startup
> > > script will help.
> > 
> > Since you installed in a non-standard location, you probably need to
> > adjust
> > paths in the config files.
> > 
> > What I would recommend is not to build and install by hand, but to use
> > their
> > package manager to build a new package with listening enabled. The
> > ./configure
> > script takes a --disable-listener parameter. So, its probably as simple as
> > deleting that in the source package and rebuilding.
> > 
> > That said, I have no idea how to build a package on Debian or Ubuntu.
> > 
> > -Steve

  reply	other threads:[~2017-10-04 15:19 UTC|newest]

Thread overview: 16+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2017-10-02 18:55 Audisp-remote - connection refused Rituraj Buddhisagar
2017-10-02 19:51 ` Rituraj Buddhisagar
2017-10-02 21:58 ` Steve Grubb
2017-10-03  3:31   ` Rituraj Buddhisagar
2017-10-03 12:44     ` Steve Grubb
2017-10-03 12:52       ` Rituraj Buddhisagar
2017-10-03 12:58         ` Rituraj Buddhisagar
2017-10-03 15:08         ` Steve Grubb
2017-10-03 18:40           ` Rituraj Buddhisagar
2017-10-03 19:08             ` Rituraj Buddhisagar
2017-10-03 20:00               ` Rituraj Buddhisagar
2017-10-03 20:22                 ` Steve Grubb
2017-10-04 14:01                   ` Rituraj Buddhisagar
2017-10-04 15:19                     ` Steve Grubb [this message]
2017-10-04 16:02                       ` Rituraj Buddhisagar
2017-10-04 16:28                         ` Steve Grubb

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=7773077.6JsVQVb1J2@x2 \
    --to=sgrubb@redhat.com \
    --cc=linux-audit@redhat.com \
    --cc=rituraj@vayana.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox