LINUXOR.SK ... open source notes ...

Vault - rsyslog.conf (load balancer)

category: solutionz · date: 2024-12-31 · updated: 2026-10-02 · author: LALA

Vault Solution · Config document · referenced from Load balancer, Audit logging and log shipping

The rsyslog configuration of the load-balancer nodes. It is the file of the other servers plus a UDP listener on the loopback address that receives HAProxy's log lines and writes them to their own file.

ItemValue
Path on the host/etc/rsyslog.conf
Deployed onboth load-balancer nodes of every cluster
HAProxy logs to127.0.0.1:514, facility local2
HAProxy log file/var/log/haproxy.log

The file

ini
###############################################################################
# File: rsyslog.conf
# Description: rsyslog configuration
# Author: admin01
# Date: 2024
#
# REF1: https://www.rsyslog.com/doc/configuration/index.html
# REF2: https://github.com/jmaas/rsyslog-configs/tree/master/8-stable
###############################################################################

###############################################################################
# Global settings
###############################################################################

#------------------------------------------------------------------------------
# Where to place auxiliary files
#------------------------------------------------------------------------------
global(
    workDirectory="/var/lib/rsyslog"
)

#------------------------------------------------------------------------------
# Include all config files in /etc/rsyslog.d/
#------------------------------------------------------------------------------
include(
    file="/etc/rsyslog.d/*.conf" mode="optional"
)

#------------------------------------------------------------------------------
# Default creation mode for files created by rsyslog
#------------------------------------------------------------------------------
$FileCreateMode 0640

###############################################################################
# Builtin modules settings - Builtin modules does not need to be loaded, but
#                            are explicitly loaded for completeness and for
#                            possibility to pass the module parameters.
###############################################################################

#------------------------------------------------------------------------------
# syslog Forwarding Output Module
#
# The omfwd plug-in provides the core functionality of traditional message
# forwarding via UDP and plain TCP.
#------------------------------------------------------------------------------
module(
    load="builtin:omfwd"
)

#------------------------------------------------------------------------------
# File Output Module
#
# The omfile plug-in provides the core functionality of writing messages to
# files residing inside the local file system (which may actually be remote
# if methods like NFS are used). Both files named with static names as well
# files with names based on message content are supported by this module.
#------------------------------------------------------------------------------
module(
    load="builtin:omfile"
        Template="RSYSLOG_TraditionalFileFormat"
)

#------------------------------------------------------------------------------
# Pipe Output Module
#
# The ompipe plug-in provides the core functionality for logging output to
# named pipes (fifos).
#------------------------------------------------------------------------------
module(
    load="builtin:ompipe"
)

###############################################################################
# Input modules settings
###############################################################################

#------------------------------------------------------------------------------
# Unix Socket Input Module
#
# Message reception via local log socket is disabled for all messages.
# Local messages are retrieved through imjournal now.
#------------------------------------------------------------------------------
module(
    load="imuxsock"
    SysSock.Use="off"
)

#------------------------------------------------------------------------------
# UDP Sylog Input Module
#
# Provides the ability to receive syslog messages via UDP.
# This is used only for Haproxy logs = listening only on localhost:514.
#------------------------------------------------------------------------------
module(
    load="imudp"
)
input(type="imudp" port="514" Address="127.0.0.1")

#------------------------------------------------------------------------------
# Systemd Journal Input Module
#
# Provides the ability to import structured log messages from systemd journal
# to syslog.
#------------------------------------------------------------------------------
module(
    load="imjournal"
    StateFile="imjournal.state"
)

###############################################################################
# Logging rules
###############################################################################

#------------------------------------------------------------------------------
# Private logs
#------------------------------------------------------------------------------
auth,authpriv.*                                          /var/log/secure

#------------------------------------------------------------------------------
# Local logs
#------------------------------------------------------------------------------
local0,local1.*                                          -/var/log/localmessages
local3.*                                                 -/var/log/localmessages
local4,local5.*                                          -/var/log/localmessages
local6,local7.*                                          -/var/log/localmessages
*.emerg                                                    :omusrmsg:*

#------------------------------------------------------------------------------
# Haproxy logs
#------------------------------------------------------------------------------
local2.*                                                 -/var/log/haproxy.log

#------------------------------------------------------------------------------
# Misc. logs
#------------------------------------------------------------------------------
*.=warning;*.=err                                        -/var/log/warn
*.crit                                                   /var/log/warn

#------------------------------------------------------------------------------
# Log all kernel messages to the console.
# Logging much else clutters up the screen.
#------------------------------------------------------------------------------
kern.*                                                   /dev/console

#------------------------------------------------------------------------------
# Log anything (except mail) of level info or higher.
# Don't log private authentication messages!
# Don't log haproxy messages.
#------------------------------------------------------------------------------
*.info;mail.none;authpriv.none;cron.none;local2.none     /var/log/messages

#------------------------------------------------------------------------------
# Log the mail messages
#------------------------------------------------------------------------------
mail.*                                                  -/var/log/maillog
mail.info                                               -/var/log/mail.info
mail.warning                                            -/var/log/mail.warning
mail.err                                                /var/log/mail.err

#------------------------------------------------------------------------------
# Log cron stuff
#------------------------------------------------------------------------------
cron.*                                                  /var/log/cron

#------------------------------------------------------------------------------
# Everybody gets emergency messages
#------------------------------------------------------------------------------
*.emerg                                                 :omusrmsg:*

#------------------------------------------------------------------------------
# news logging
#------------------------------------------------------------------------------
news.crit                                               -/var/log/news/news.crit
news.notice                                             -/var/log/news/news.crit
uucp,news.crit                                          /var/log/spooler

#------------------------------------------------------------------------------
# Save boot messages also to boot.log
#------------------------------------------------------------------------------
local7.*                                                /var/log/boot.log

#------------------------------------------------------------------------------
# Forwarding messages to SIEM (SIEM)
#
# c001 - Proxy-IP 10.40.2.11 = log-collector.example.net in /etc/hosts
# c002 - Proxy-IP 10.40.8.44
# c003 - Proxy-IP 10.40.8.11
# c004 - Proxy-IP 10.40.8.19
# c006 - Proxy-IP 10.40.8.24
# c008 - Proxy-IP 10.40.8.35
#
# REF3: <internal wiki link removed>
#------------------------------------------------------------------------------

$template SyslogFormatSIEM,"<%PRI%>%TIMESTAMP:::date-rfc3339% %HOSTNAME% %syslogtag:1:32%%msg:::sp-if-no-1st-sp%%msg:::drop-last-lf%\n"

$ActionResumeRetryCount -1
$ActionQueueType LinkedList
$ActionQueueSize 50000
$ActionQueueDiscardMark 45000
$ActionQueueSaveOnShutdown on

auth.info               @@log-collector.example.net:50515;SyslogFormatSIEM
authpriv.*              @@log-collector.example.net:50515;SyslogFormatSIEM
cron.info               @@log-collector.example.net:50515;SyslogFormatSIEM
syslog.=info            @@log-collector.example.net:50515;SyslogFormatSIEM
local5.*                @@log-collector.example.net:50515;SyslogFormatSIEM
local6.*                @@log-collector.example.net:50515;SyslogFormatSIEM
*.emerg                 @@log-collector.example.net:50515;SyslogFormatSIEM

What differs from the other servers

DifferenceReason
imudp module with an input on 127.0.0.1:514HAProxy, inside its chroot, logs over UDP to the loopback address
local2.* goes to /var/log/haproxy.log and is excluded from /var/log/messagesOne connection log per line would drown everything else
local1. to local4. are not forwarded to the collectorThe connection log stays on the host; only security facilities leave it
← solutionz