Vault - rsyslog.conf (Vault node and bastion)
Vault Solution · Config document · referenced from Audit logging and log shipping
The rsyslog configuration of the Vault nodes and the bastion hosts. It sorts local messages into files and forwards the security-relevant facilities over TCP to the central collector of the security operations centre.
| Item | Value |
|---|---|
| Path on the host | /etc/rsyslog.conf |
| Deployed on | Vault nodes and bastion hosts |
| Forwards to | log-collector.example.net, TCP 50515 |
| SELinux | semanage port -a -t syslogd_port_t -p tcp 50515 |
| Applied with | systemctl restart rsyslog |
The file
############################################################################### # File: rsyslog.conf # Description: rsyslog configuration # Author: admin01 # Date: 2024 # # REF1: https://www.rsyslog.com/doc/configuration/index.html # REF2: https://github.com/jmaas/rsyslog-configs/tree/master/8-stable ############################################################################### ############################################################################### # Global settings ############################################################################### #------------------------------------------------------------------------------ # Where to place auxiliary files #------------------------------------------------------------------------------ global( workDirectory="/var/lib/rsyslog" ) #------------------------------------------------------------------------------ # Include all config files in /etc/rsyslog.d/ #------------------------------------------------------------------------------ include( file="/etc/rsyslog.d/*.conf" mode="optional" ) #------------------------------------------------------------------------------ # Default creation mode for files created by rsyslog #------------------------------------------------------------------------------ $FileCreateMode 0640 ############################################################################### # Builtin modules settings - Builtin modules does not need to be loaded, but # are explicitly loaded for completeness and for # possibility to pass the module parameters. ############################################################################### #------------------------------------------------------------------------------ # syslog Forwarding Output Module # # The omfwd plug-in provides the core functionality of traditional message # forwarding via UDP and plain TCP. #------------------------------------------------------------------------------ module( load="builtin:omfwd" ) #------------------------------------------------------------------------------ # File Output Module # # The omfile plug-in provides the core functionality of writing messages to # files residing inside the local file system (which may actually be remote # if methods like NFS are used). Both files named with static names as well # files with names based on message content are supported by this module. #------------------------------------------------------------------------------ module( load="builtin:omfile" Template="RSYSLOG_TraditionalFileFormat" ) #------------------------------------------------------------------------------ # Pipe Output Module # # The ompipe plug-in provides the core functionality for logging output to # named pipes (fifos). #------------------------------------------------------------------------------ module( load="builtin:ompipe" ) ############################################################################### # Input modules settings ############################################################################### #------------------------------------------------------------------------------ # Unix Socket Input Module # # Message reception via local log socket is disabled for all messages. # Local messages are retrieved through imjournal now. #------------------------------------------------------------------------------ module( load="imuxsock" SysSock.Use="off" ) #------------------------------------------------------------------------------ # Systemd Journal Input Module # # Provides the ability to import structured log messages from systemd journal # to syslog. #------------------------------------------------------------------------------ module( load="imjournal" StateFile="imjournal.state" ) ############################################################################### # Logging rules ############################################################################### #------------------------------------------------------------------------------ # Private logs #------------------------------------------------------------------------------ auth,authpriv.* /var/log/secure #------------------------------------------------------------------------------ # Local logs #------------------------------------------------------------------------------ local0,local1.* -/var/log/localmessages local2,local3.* -/var/log/localmessages local4,local5.* -/var/log/localmessages local6,local7.* -/var/log/localmessages *.emerg :omusrmsg:* #------------------------------------------------------------------------------ # Misc. logs #------------------------------------------------------------------------------ *.=warning;*.=err -/var/log/warn *.crit /var/log/warn #------------------------------------------------------------------------------ # Log all kernel messages to the console. # Logging much else clutters up the screen. #------------------------------------------------------------------------------ kern.* /dev/console #------------------------------------------------------------------------------ # Log anything (except mail) of level info or higher. # Don't log private authentication messages! # Don't log haproxy messages. #------------------------------------------------------------------------------ *.info;mail.none;authpriv.none;cron.none /var/log/messages #------------------------------------------------------------------------------ # Log the mail messages #------------------------------------------------------------------------------ mail.* -/var/log/maillog mail.info -/var/log/mail.info mail.warning -/var/log/mail.warning mail.err /var/log/mail.err #------------------------------------------------------------------------------ # Log cron stuff #------------------------------------------------------------------------------ cron.* /var/log/cron #------------------------------------------------------------------------------ # Everybody gets emergency messages #------------------------------------------------------------------------------ *.emerg :omusrmsg:* #------------------------------------------------------------------------------ # news logging #------------------------------------------------------------------------------ news.crit -/var/log/news/news.crit news.notice -/var/log/news/news.crit uucp,news.crit /var/log/spooler #------------------------------------------------------------------------------ # Save boot messages also to boot.log #------------------------------------------------------------------------------ local7.* /var/log/boot.log #------------------------------------------------------------------------------ # Forwarding messages to SIEM (SIEM) # # c001 - Proxy-IP 10.40.2.11 = log-collector.example.net in /etc/hosts # c002 - Proxy-IP 10.40.8.44 # c003 - Proxy-IP 10.40.8.11 # c004 - Proxy-IP 10.40.8.19 # c006 - Proxy-IP 10.40.8.24 # c008 - Proxy-IP 10.40.8.35 # # REF3: <internal wiki link removed> #------------------------------------------------------------------------------ $template SyslogFormatSIEM,"<%PRI%>%TIMESTAMP:::date-rfc3339% %HOSTNAME% %syslogtag:1:32%%msg:::sp-if-no-1st-sp%%msg:::drop-last-lf%\n" $ActionResumeRetryCount -1 $ActionQueueType LinkedList $ActionQueueSize 50000 $ActionQueueDiscardMark 45000 $ActionQueueSaveOnShutdown on auth.info @@log-collector.example.net:50515;SyslogFormatSIEM authpriv.* @@log-collector.example.net:50515;SyslogFormatSIEM cron.info @@log-collector.example.net:50515;SyslogFormatSIEM syslog.=info @@log-collector.example.net:50515;SyslogFormatSIEM local1.* @@log-collector.example.net:50515;SyslogFormatSIEM local2.* @@log-collector.example.net:50515;SyslogFormatSIEM local3.* @@log-collector.example.net:50515;SyslogFormatSIEM local4.* @@log-collector.example.net:50515;SyslogFormatSIEM local5.* @@log-collector.example.net:50515;SyslogFormatSIEM local6.* @@log-collector.example.net:50515;SyslogFormatSIEM *.emerg @@log-collector.example.net:50515;SyslogFormatSIEM
What is forwarded
| Selector | Source |
|---|---|
auth.info, authpriv.* | Logins, sudo, PAM |
cron.info | Scheduled jobs |
syslog.=info | rsyslog's own messages |
local1. to local5. | Application facilities |
local6.* | Linux audit daemon, redirected by /etc/audit/plugins.d/syslog.conf |
*.emerg | Emergencies of any facility |
The queue settings in front of the forwarding rules keep up to 50,000 messages in memory and on disk across a restart, so an unreachable collector delays messages instead of blocking the host.