NXlog im_wseventing报错:请求的HTTP服务票据在keytab中不存在
尝试通过Kerberos认证,用NXlog将Windows事件日志收集到Ubuntu 22桌面。环境包含三台虚拟机:Windows 10(WEC客户端)、主机名linux-wec的Ubuntu桌面(WEC服务器)、主机名ADSERVER的Windows Server 2019(提供AD+DNS服务),所有设备互通。完成配置后重启nxlog服务,日志中出现以下错误:
ERROR [im_wseventing|windows_events] GSS-API error gss_accept_sec_context - type: major code: 851968, msg: Unspecified GSS failure. Minor code may provide more information ERROR [im_wseventing|windows_events] GSS-API error gss_accept_sec_context - type: minor code: -1765328349, msg: Request ticket server HTTP/linux-wec.abc.local@ABC.LOCAL not found in keytab (ticket kvno 7)
已尝试修改加密方式、重新获取票据、重新配置所有步骤,问题仍未解决。
相关配置文件
krb5.conf
[libdefaults] default_realm = ABC.LOCAL # The following krb5.conf variables are only for MIT Kerberos. kdc_timesync = 1 ccache_type = 4 forwardable = true proxiable = true # The following encryption type specification will be used by MIT Kerberos # if uncommented. In general, the defaults in the MIT Kerberos code are # correct and overriding these specifications only serves to disable new # encryption types as they are added, creating interoperability problems. # # The only time when you might need to uncomment these lines and change # the enctypes is if you have local software that will break on ticket # caches containing ticket encryption types it doesn't know about (such as # old versions of Sun Java). # default_tgs_enctypes = des3-hmac-sha1 # default_tkt_enctypes = des3-hmac-sha1 # permitted_enctypes = des3-hmac-sha1 # The following libdefaults parameters are only for Heimdal Kerberos. fcc-mit-ticketflags = true [realms] ABC.LOCAL = { kdc = ADSERVER.abc.local admin_server = ADSERVER.abc.local } ATHENA.MIT.EDU = { kdc = kerberos.mit.edu kdc = kerberos-1.mit.edu kdc = kerberos-2.mit.edu:88 admin_server = kerberos.mit.edu default_domain = mit.edu } ZONE.MIT.EDU = { kdc = casio.mit.edu kdc = seiko.mit.edu admin_server = casio.mit.edu } CSAIL.MIT.EDU = { admin_server = kerberos.csail.mit.edu default_domain = csail.mit.edu } IHTFP.ORG = { kdc = kerberos.ihtfp.org admin_server = kerberos.ihtfp.org } 1TS.ORG = { kdc = kerberos.1ts.org admin_server = kerberos.1ts.org } ANDREW.CMU.EDU = { admin_server = kerberos.andrew.cmu.edu default_domain = andrew.cmu.edu } CS.CMU.EDU = { kdc = kerberos-1.srv.cs.cmu.edu kdc = kerberos-2.srv.cs.cmu.edu kdc = kerberos-3.srv.cs.cmu.edu admin_server = kerberos.cs.cmu.edu } DEMENTIA.ORG = { kdc = kerberos.dementix.org kdc = kerberos2.dementix.org admin_server = kerberos.dementix.org } stanford.edu = { kdc = krb5auth1.stanford.edu kdc = krb5auth2.stanford.edu kdc = krb5auth3.stanford.edu master_kdc = krb5auth1.stanford.edu admin_server = krb5-admin.stanford.edu default_domain = stanford.edu } UTORONTO.CA = { kdc = kerberos1.utoronto.ca kdc = kerberos2.utoronto.ca kdc = kerberos3.utoronto.ca admin_server = kerberos1.utoronto.ca default_domain = utoronto.ca } [domain_realm] .mit.edu = ATHENA.MIT.EDU mit.edu = ATHENA.MIT.EDU .media.mit.edu = MEDIA-LAB.MIT.EDU media.mit.edu = MEDIA-LAB.MIT.EDU .csail.mit.edu = CSAIL.MIT.EDU csail.mit.edu = CSAIL.MIT.EDU .whoi.edu = ATHENA.MIT.EDU whoi.edu = ATHENA.MIT.EDU .stanford.edu = stanford.edu .slac.stanford.edu = SLAC.STANFORD.EDU .toronto.edu = UTORONTO.CA .utoronto.ca = UTORONTO.CA .abc.local = ABC.LOCAL abc.local = ABC.LOCAL
nxlog.conf
User nxlog Group nxlog Panic Soft # default values: define INSTALLDIR /opt/nxlog # PidFile %INSTALLDIR%/var/run/nxlog/nxlog.pid # CacheDir %INSTALLDIR%/var/spool/nxlog # ModuleDir %INSTALLDIR%/lib/nxlog/modules # SpoolDir %INSTALLDIR%/var/spool/nxlog define CERTDIR %INSTALLDIR%/var/lib/nxlog/cert define CONFDIR %INSTALLDIR%/etc/nxlog.d # Note that these two lines define constants only; the log file location # is ultimately set by the `LogFile` directive (see below). The # `MYLOGFILE` define is also used to rotate the log file automatically # (see the `_fileop` block). define LOGDIR %INSTALLDIR%/var/log/nxlog define MYLOGFILE %LOGDIR%/nxlog.log # If you are not using NXLog Manager, disable the `include` line # and enable LogLevel and LogFile. #include %CONFDIR%/*.conf LogLevel INFO LogFile %MYLOGFILE% <Extension _syslog> Module xm_syslog </Extension> # This block rotates `%MYLOGFILE%` on a schedule. Note that if `LogFile` # is changed in managed.conf via NXLog Manager, rotation of the new # file should also be configured there. <Extension _fileop> Module xm_fileop # Check the size of our log file hourly, rotate if larger than 5MB <Schedule> Every 1 hour <Exec> if ( file_exists('%MYLOGFILE%') and (file_size('%MYLOGFILE%') >= 5M) ) { file_cycle('%MYLOGFILE%', 8); } </Exec> </Schedule> # Rotate our log file every week on Sunday at midnight <Schedule> When @weekly Exec if file_exists('%MYLOGFILE%') file_cycle('%MYLOGFILE%', 8); </Schedule> </Extension> <Input windows_events> Module im_wseventing Address http://linux-wec.abc.local:80/wsman/ ListenAddr 0.0.0.0 Port 80 <QueryXML> <QueryList> <Query Id="0"> <Select Path="Application">*</Select> <Select Path="Security">*</Select> <Select Path="Setup">*</Select> <Select Path="System">*</Select> <Select Path="ForwardedEvents">*</Select> <Select Path="Windows PowerShell">*</Select> </Query> </QueryList> </QueryXML> # Log connections for testing and troubleshooting LogConnections TRUE </Input> <Output file> Module om_file File "%LOGDIR%/windows.log" </Output> <Route uds_to_file> Path windows_events => file </Route>
补充信息
- ADSERVER和WEC客户端均加入
abc.local域 - 已为
linux-wec配置DNS正向及反向记录 - 已在ADSERVER的AD用户和计算机中创建
linux-wec账户 - WEC客户端组策略配置:
计算机配置>管理模板>Windows组件>事件转发>配置目标订阅管理器已启用,设置值为:
Server=HTTP://linux-wec.abc.local:80/wsman/,Refresh=30
错误核心是keytab文件中缺少HTTP/linux-wec.abc.local@ABC.LOCAL的票据,按以下步骤修复:
1. 确认服务主体名称(SPN)配置
在ADSERVER上以域管理员身份执行PowerShell命令,检查linux-wec账户是否绑定正确的SPN:
setspn -L linux-wec
需确保输出包含HTTP/linux-wec.abc.local和HTTP/linux-wec。如果缺失,执行以下命令添加:
setspn -A HTTP/linux-wec.abc.local linux-wec setspn -A HTTP/linux-wec linux-wec
2. 重新生成keytab文件
在ADSERVER上执行以下命令生成keytab(替换/path/to/save/linux-wec.keytab为实际保存路径):
ktpass /princ HTTP/linux-wec.abc.local@ABC.LOCAL /mapuser linux-wec@ABC.LOCAL /pass * /out /path/to/save/linux-wec.keytab /crypto ALL /ptype KRB5_NT_PRINCIPAL /kvno 7
/kvno 7需匹配错误日志中的ticket kvno 7- 输入
linux-wec账户密码时确保正确
3. 传输keytab到Ubuntu服务器
用scp或其他方式将生成的keytab文件传到linux-wec服务器,建议放在/etc/krb5.keytab路径。
4. 配置nxlog使用keytab
修改nxlog.conf的<Input windows_events>块,添加Kerberos相关配置:
<Input windows_events> Module im_wseventing Address http://linux-wec.abc.local:80/wsman/ ListenAddr 0.0.0.0 Port 80 # 添加Kerberos配置 Kerberos TRUE KeytabFile /etc/krb5.keytab # 替换为你的keytab实际路径 ServicePrincipalName HTTP/linux-wec.abc.local <QueryXML> <!-- 原QueryXML内容保持不变 --> </QueryXML> LogConnections TRUE </Input>
5. 设置keytab文件权限
确保nxlog用户能读取keytab文件:
sudo chown nxlog:nxlog /etc/krb5.keytab sudo chmod 600 /etc/krb5.keytab
6. 验证Kerberos票据
在Ubuntu服务器上执行以下命令验证keytab有效性:
kinit -kt /etc/krb5.keytab HTTP/linux-wec.abc.local@ABC.LOCAL klist
如果输出包含有效票据,说明keytab配置正确。
7. 重启nxlog服务
sudo systemctl restart nxlog
查看日志确认错误是否消失:
tail -f /opt/nxlog/var/log/nxlog/nxlog.log
额外排查点
- 确保Ubuntu服务器系统时间与AD服务器同步(Kerberos允许最大5分钟时间差)
- 检查krb5.conf中
default_realm为大写ABC.LOCAL,与AD域一致 - 确认WEC客户端组策略中的服务器地址与nxlog配置的
Address完全匹配(包括大小写、端口)
内容的提问来源于stack exchange,提问作者NTSO

