LINUXOR.SK ... open source notes ...

Vault - rsyslog.conf (Vault node and bastion)

category: solutionz · date: 2024-12-31 · updated: 2026-10-02 · author: LALA

Vault Solution · Config document · referenced from Audit logging and log shipping

The rsyslog configuration of the Vault nodes and the bastion hosts. It sorts local messages into files and forwards the security-relevant facilities over TCP to the central collector of the security operations centre.

ItemValue
Path on the host/etc/rsyslog.conf
Deployed onVault nodes and bastion hosts
Forwards tolog-collector.example.net, TCP 50515
SELinuxsemanage port -a -t syslogd_port_t -p tcp 50515
Applied withsystemctl restart rsyslog

The file

ini
###############################################################################
# File: rsyslog.conf
# Description: rsyslog configuration
# Author: admin01
# Date: 2024
#
# REF1: https://www.rsyslog.com/doc/configuration/index.html
# REF2: https://github.com/jmaas/rsyslog-configs/tree/master/8-stable
###############################################################################

###############################################################################
# Global settings
###############################################################################

#------------------------------------------------------------------------------
# Where to place auxiliary files
#------------------------------------------------------------------------------
global(
    workDirectory="/var/lib/rsyslog"
)

#------------------------------------------------------------------------------
# Include all config files in /etc/rsyslog.d/
#------------------------------------------------------------------------------
include(
    file="/etc/rsyslog.d/*.conf" mode="optional"
)

#------------------------------------------------------------------------------
# Default creation mode for files created by rsyslog
#------------------------------------------------------------------------------
$FileCreateMode 0640

###############################################################################
# Builtin modules settings - Builtin modules does not need to be loaded, but
#                            are explicitly loaded for completeness and for
#                            possibility to pass the module parameters.
###############################################################################

#------------------------------------------------------------------------------
# syslog Forwarding Output Module
#
# The omfwd plug-in provides the core functionality of traditional message
# forwarding via UDP and plain TCP.
#------------------------------------------------------------------------------
module(
    load="builtin:omfwd"
)

#------------------------------------------------------------------------------
# File Output Module
#
# The omfile plug-in provides the core functionality of writing messages to
# files residing inside the local file system (which may actually be remote
# if methods like NFS are used). Both files named with static names as well
# files with names based on message content are supported by this module.
#------------------------------------------------------------------------------
module(
    load="builtin:omfile"
        Template="RSYSLOG_TraditionalFileFormat"
)

#------------------------------------------------------------------------------
# Pipe Output Module
#
# The ompipe plug-in provides the core functionality for logging output to
# named pipes (fifos).
#------------------------------------------------------------------------------
module(
    load="builtin:ompipe"
)

###############################################################################
# Input modules settings
###############################################################################

#------------------------------------------------------------------------------
# Unix Socket Input Module
#
# Message reception via local log socket is disabled for all messages.
# Local messages are retrieved through imjournal now.
#------------------------------------------------------------------------------
module(
    load="imuxsock"
    SysSock.Use="off"
)

#------------------------------------------------------------------------------
# Systemd Journal Input Module
#
# Provides the ability to import structured log messages from systemd journal
# to syslog.
#------------------------------------------------------------------------------
module(
    load="imjournal"
    StateFile="imjournal.state"
)

###############################################################################
# Logging rules
###############################################################################

#------------------------------------------------------------------------------
# Private logs
#------------------------------------------------------------------------------
auth,authpriv.*                                          /var/log/secure

#------------------------------------------------------------------------------
# Local logs
#------------------------------------------------------------------------------
local0,local1.*                                          -/var/log/localmessages
local2,local3.*                                          -/var/log/localmessages
local4,local5.*                                          -/var/log/localmessages
local6,local7.*                                          -/var/log/localmessages
*.emerg                                                    :omusrmsg:*

#------------------------------------------------------------------------------
# Misc. logs
#------------------------------------------------------------------------------
*.=warning;*.=err                                        -/var/log/warn
*.crit                                                   /var/log/warn

#------------------------------------------------------------------------------
# Log all kernel messages to the console.
# Logging much else clutters up the screen.
#------------------------------------------------------------------------------
kern.*                                                   /dev/console

#------------------------------------------------------------------------------
# Log anything (except mail) of level info or higher.
# Don't log private authentication messages!
# Don't log haproxy messages.
#------------------------------------------------------------------------------
*.info;mail.none;authpriv.none;cron.none                /var/log/messages

#------------------------------------------------------------------------------
# Log the mail messages
#------------------------------------------------------------------------------
mail.*                                                  -/var/log/maillog
mail.info                                               -/var/log/mail.info
mail.warning                                            -/var/log/mail.warning
mail.err                                                /var/log/mail.err

#------------------------------------------------------------------------------
# Log cron stuff
#------------------------------------------------------------------------------
cron.*                                                  /var/log/cron

#------------------------------------------------------------------------------
# Everybody gets emergency messages
#------------------------------------------------------------------------------
*.emerg                                                 :omusrmsg:*

#------------------------------------------------------------------------------
# news logging
#------------------------------------------------------------------------------
news.crit                                               -/var/log/news/news.crit
news.notice                                             -/var/log/news/news.crit
uucp,news.crit                                          /var/log/spooler

#------------------------------------------------------------------------------
# Save boot messages also to boot.log
#------------------------------------------------------------------------------
local7.*                                                /var/log/boot.log

#------------------------------------------------------------------------------
# Forwarding messages to SIEM (SIEM)
#
# c001 - Proxy-IP 10.40.2.11 = log-collector.example.net in /etc/hosts
# c002 - Proxy-IP 10.40.8.44
# c003 - Proxy-IP 10.40.8.11
# c004 - Proxy-IP 10.40.8.19
# c006 - Proxy-IP 10.40.8.24
# c008 - Proxy-IP 10.40.8.35
#
# REF3: <internal wiki link removed>
#------------------------------------------------------------------------------

$template SyslogFormatSIEM,"<%PRI%>%TIMESTAMP:::date-rfc3339% %HOSTNAME% %syslogtag:1:32%%msg:::sp-if-no-1st-sp%%msg:::drop-last-lf%\n"

$ActionResumeRetryCount -1
$ActionQueueType LinkedList
$ActionQueueSize 50000
$ActionQueueDiscardMark 45000
$ActionQueueSaveOnShutdown on

auth.info               @@log-collector.example.net:50515;SyslogFormatSIEM
authpriv.*              @@log-collector.example.net:50515;SyslogFormatSIEM
cron.info               @@log-collector.example.net:50515;SyslogFormatSIEM
syslog.=info            @@log-collector.example.net:50515;SyslogFormatSIEM
local1.*                @@log-collector.example.net:50515;SyslogFormatSIEM
local2.*                @@log-collector.example.net:50515;SyslogFormatSIEM
local3.*                @@log-collector.example.net:50515;SyslogFormatSIEM
local4.*                @@log-collector.example.net:50515;SyslogFormatSIEM
local5.*                @@log-collector.example.net:50515;SyslogFormatSIEM
local6.*                @@log-collector.example.net:50515;SyslogFormatSIEM
*.emerg                 @@log-collector.example.net:50515;SyslogFormatSIEM

What is forwarded

SelectorSource
auth.info, authpriv.*Logins, sudo, PAM
cron.infoScheduled jobs
syslog.=inforsyslog's own messages
local1. to local5.Application facilities
local6.*Linux audit daemon, redirected by /etc/audit/plugins.d/syslog.conf
*.emergEmergencies of any facility

The queue settings in front of the forwarding rules keep up to 50,000 messages in memory and on disk across a restart, so an unreachable collector delays messages instead of blocking the host.

← solutionz