Vault - rsyslog.conf (load balancer)
Vault Solution · Config document · referenced from Load balancer, Audit logging and log shipping
The rsyslog configuration of the load-balancer nodes. It is the file of the other servers plus a UDP listener on the loopback address that receives HAProxy's log lines and writes them to their own file.
| Item | Value |
|---|---|
| Path on the host | /etc/rsyslog.conf |
| Deployed on | both load-balancer nodes of every cluster |
| HAProxy logs to | 127.0.0.1:514, facility local2 |
| HAProxy log file | /var/log/haproxy.log |
The file
############################################################################### # File: rsyslog.conf # Description: rsyslog configuration # Author: admin01 # Date: 2024 # # REF1: https://www.rsyslog.com/doc/configuration/index.html # REF2: https://github.com/jmaas/rsyslog-configs/tree/master/8-stable ############################################################################### ############################################################################### # Global settings ############################################################################### #------------------------------------------------------------------------------ # Where to place auxiliary files #------------------------------------------------------------------------------ global( workDirectory="/var/lib/rsyslog" ) #------------------------------------------------------------------------------ # Include all config files in /etc/rsyslog.d/ #------------------------------------------------------------------------------ include( file="/etc/rsyslog.d/*.conf" mode="optional" ) #------------------------------------------------------------------------------ # Default creation mode for files created by rsyslog #------------------------------------------------------------------------------ $FileCreateMode 0640 ############################################################################### # Builtin modules settings - Builtin modules does not need to be loaded, but # are explicitly loaded for completeness and for # possibility to pass the module parameters. ############################################################################### #------------------------------------------------------------------------------ # syslog Forwarding Output Module # # The omfwd plug-in provides the core functionality of traditional message # forwarding via UDP and plain TCP. #------------------------------------------------------------------------------ module( load="builtin:omfwd" ) #------------------------------------------------------------------------------ # File Output Module # # The omfile plug-in provides the core functionality of writing messages to # files residing inside the local file system (which may actually be remote # if methods like NFS are used). Both files named with static names as well # files with names based on message content are supported by this module. #------------------------------------------------------------------------------ module( load="builtin:omfile" Template="RSYSLOG_TraditionalFileFormat" ) #------------------------------------------------------------------------------ # Pipe Output Module # # The ompipe plug-in provides the core functionality for logging output to # named pipes (fifos). #------------------------------------------------------------------------------ module( load="builtin:ompipe" ) ############################################################################### # Input modules settings ############################################################################### #------------------------------------------------------------------------------ # Unix Socket Input Module # # Message reception via local log socket is disabled for all messages. # Local messages are retrieved through imjournal now. #------------------------------------------------------------------------------ module( load="imuxsock" SysSock.Use="off" ) #------------------------------------------------------------------------------ # UDP Sylog Input Module # # Provides the ability to receive syslog messages via UDP. # This is used only for Haproxy logs = listening only on localhost:514. #------------------------------------------------------------------------------ module( load="imudp" ) input(type="imudp" port="514" Address="127.0.0.1") #------------------------------------------------------------------------------ # Systemd Journal Input Module # # Provides the ability to import structured log messages from systemd journal # to syslog. #------------------------------------------------------------------------------ module( load="imjournal" StateFile="imjournal.state" ) ############################################################################### # Logging rules ############################################################################### #------------------------------------------------------------------------------ # Private logs #------------------------------------------------------------------------------ auth,authpriv.* /var/log/secure #------------------------------------------------------------------------------ # Local logs #------------------------------------------------------------------------------ local0,local1.* -/var/log/localmessages local3.* -/var/log/localmessages local4,local5.* -/var/log/localmessages local6,local7.* -/var/log/localmessages *.emerg :omusrmsg:* #------------------------------------------------------------------------------ # Haproxy logs #------------------------------------------------------------------------------ local2.* -/var/log/haproxy.log #------------------------------------------------------------------------------ # Misc. logs #------------------------------------------------------------------------------ *.=warning;*.=err -/var/log/warn *.crit /var/log/warn #------------------------------------------------------------------------------ # Log all kernel messages to the console. # Logging much else clutters up the screen. #------------------------------------------------------------------------------ kern.* /dev/console #------------------------------------------------------------------------------ # Log anything (except mail) of level info or higher. # Don't log private authentication messages! # Don't log haproxy messages. #------------------------------------------------------------------------------ *.info;mail.none;authpriv.none;cron.none;local2.none /var/log/messages #------------------------------------------------------------------------------ # Log the mail messages #------------------------------------------------------------------------------ mail.* -/var/log/maillog mail.info -/var/log/mail.info mail.warning -/var/log/mail.warning mail.err /var/log/mail.err #------------------------------------------------------------------------------ # Log cron stuff #------------------------------------------------------------------------------ cron.* /var/log/cron #------------------------------------------------------------------------------ # Everybody gets emergency messages #------------------------------------------------------------------------------ *.emerg :omusrmsg:* #------------------------------------------------------------------------------ # news logging #------------------------------------------------------------------------------ news.crit -/var/log/news/news.crit news.notice -/var/log/news/news.crit uucp,news.crit /var/log/spooler #------------------------------------------------------------------------------ # Save boot messages also to boot.log #------------------------------------------------------------------------------ local7.* /var/log/boot.log #------------------------------------------------------------------------------ # Forwarding messages to SIEM (SIEM) # # c001 - Proxy-IP 10.40.2.11 = log-collector.example.net in /etc/hosts # c002 - Proxy-IP 10.40.8.44 # c003 - Proxy-IP 10.40.8.11 # c004 - Proxy-IP 10.40.8.19 # c006 - Proxy-IP 10.40.8.24 # c008 - Proxy-IP 10.40.8.35 # # REF3: <internal wiki link removed> #------------------------------------------------------------------------------ $template SyslogFormatSIEM,"<%PRI%>%TIMESTAMP:::date-rfc3339% %HOSTNAME% %syslogtag:1:32%%msg:::sp-if-no-1st-sp%%msg:::drop-last-lf%\n" $ActionResumeRetryCount -1 $ActionQueueType LinkedList $ActionQueueSize 50000 $ActionQueueDiscardMark 45000 $ActionQueueSaveOnShutdown on auth.info @@log-collector.example.net:50515;SyslogFormatSIEM authpriv.* @@log-collector.example.net:50515;SyslogFormatSIEM cron.info @@log-collector.example.net:50515;SyslogFormatSIEM syslog.=info @@log-collector.example.net:50515;SyslogFormatSIEM local5.* @@log-collector.example.net:50515;SyslogFormatSIEM local6.* @@log-collector.example.net:50515;SyslogFormatSIEM *.emerg @@log-collector.example.net:50515;SyslogFormatSIEM
What differs from the other servers
| Difference | Reason |
|---|---|
imudp module with an input on 127.0.0.1:514 | HAProxy, inside its chroot, logs over UDP to the loopback address |
local2.* goes to /var/log/haproxy.log and is excluded from /var/log/messages | One connection log per line would drown everything else |
local1. to local4. are not forwarded to the collector | The connection log stays on the host; only security facilities leave it |