LinuxQuestions.org
Review your favorite Linux distribution.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-24-2009, 08:04 PM   #1
Rossonero224
LQ Newbie
 
Registered: Dec 2009
Posts: 4

Rep: Reputation: 0
How to save audit logs to remote host.


Good morning everybody.
I am building an centre audit system. It means that I have to get the audit logs from kernel and collect all of them to a centre log server.

I used Centos 5.4 and audit-1.7. The "auditd" worked very well and I could easily get audit log in each host. But the problem is "collect audit logs to centre log server".
I had 2 solution for it.
+ The 1st solution is stop "auditd" and I can get audit log pass into syslogd and easily collect all of them to a centre log server. But the format of audit log that I got is changed so that I can't use some tool which come belong with auditd(ausearch and aureport) to make the audit log to be humanable. I don't like that.
+ The 2nd solution is use "audispd" and "audispd-remote" but I don't know how to config them.
Can any one give me an idea.
Thanks
 
Old 12-25-2009, 01:13 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1984Reputation: 1984Reputation: 1984Reputation: 1984Reputation: 1984Reputation: 1984Reputation: 1984Reputation: 1984Reputation: 1984Reputation: 1984Reputation: 1984
i'd suggest you persist with syslog, just need some fine tuning on the formatting on the central server. Personally I'd recommend syslog-ng centrally to allow a lot of control of the formats and file locations.
 
1 members found this post helpful.
Old 12-28-2009, 01:20 AM   #3
Rossonero224
LQ Newbie
 
Registered: Dec 2009
Posts: 4

Original Poster
Rep: Reputation: 0
Quote:
Originally Posted by acid_kewpie View Post
i'd suggest you persist with syslog, just need some fine tuning on the formatting on the central server. Personally I'd recommend syslog-ng centrally to allow a lot of control of the formats and file locations.
Thanks for your reply.
This feature of syslog-ng is great and I can remove some info in log message that I don't need.
But what about the 2nd solution? Has anynone ever configured audispd and dispathcer for auditd?
 
  


Reply

Tags
audit


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Account Locked After Exceeding Max Logins Not Recorded in Audit Logs mccartjd Linux - Security 1 11-10-2009 03:59 PM
What logs are needed for an audit trail and where can I see an example of one? abefroman Linux - Security 4 08-06-2008 08:25 AM
GUI to view audit logs mgk720 Linux - Security 3 01-29-2008 07:41 PM
LXer: Tips from an RHCE: Visualizing audit logs with mkbar LXer Syndicated Linux News 0 01-23-2008 12:41 AM
Resolving <www.some remote host>.... failed: Host not found. koodoo Linux - Newbie 2 06-27-2005 08:48 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:46 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration