You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

NXlog im_wseventing报错:请求的HTTP服务票据在keytab中不存在

问题描述

尝试通过Kerberos认证,用NXlog将Windows事件日志收集到Ubuntu 22桌面。环境包含三台虚拟机:Windows 10(WEC客户端)、主机名linux-wec的Ubuntu桌面(WEC服务器)、主机名ADSERVER的Windows Server 2019(提供AD+DNS服务),所有设备互通。完成配置后重启nxlog服务,日志中出现以下错误:

ERROR [im_wseventing|windows_events] GSS-API error gss_accept_sec_context - type: major code: 851968, msg: Unspecified GSS failure.  Minor code may provide more information

ERROR [im_wseventing|windows_events] GSS-API error gss_accept_sec_context - type: minor code: -1765328349, msg: Request ticket server HTTP/linux-wec.abc.local@ABC.LOCAL not found in keytab (ticket kvno 7)

已尝试修改加密方式、重新获取票据、重新配置所有步骤,问题仍未解决。


相关配置文件

krb5.conf

[libdefaults]
    default_realm = ABC.LOCAL
# The following krb5.conf variables are only for MIT Kerberos.
    kdc_timesync = 1
    ccache_type = 4
    forwardable = true
    proxiable = true
# The following encryption type specification will be used by MIT Kerberos
# if uncommented.  In general, the defaults in the MIT Kerberos code are
# correct and overriding these specifications only serves to disable new
# encryption types as they are added, creating interoperability problems.
#
# The only time when you might need to uncomment these lines and change
# the enctypes is if you have local software that will break on ticket
# caches containing ticket encryption types it doesn't know about (such as
# old versions of Sun Java).
#   default_tgs_enctypes = des3-hmac-sha1
#   default_tkt_enctypes = des3-hmac-sha1
#   permitted_enctypes = des3-hmac-sha1
# The following libdefaults parameters are only for Heimdal Kerberos.
    fcc-mit-ticketflags = true
[realms]
    ABC.LOCAL = {
        kdc = ADSERVER.abc.local
        admin_server = ADSERVER.abc.local
    }
    ATHENA.MIT.EDU = {
        kdc = kerberos.mit.edu
        kdc = kerberos-1.mit.edu
        kdc = kerberos-2.mit.edu:88
        admin_server = kerberos.mit.edu
        default_domain = mit.edu
    }
    ZONE.MIT.EDU = {
        kdc = casio.mit.edu
        kdc = seiko.mit.edu
        admin_server = casio.mit.edu
    }
    CSAIL.MIT.EDU = {
        admin_server = kerberos.csail.mit.edu
        default_domain = csail.mit.edu
    }
    IHTFP.ORG = {
        kdc = kerberos.ihtfp.org
        admin_server = kerberos.ihtfp.org
    }
    1TS.ORG = {
        kdc = kerberos.1ts.org
        admin_server = kerberos.1ts.org
    }
    ANDREW.CMU.EDU = {
        admin_server = kerberos.andrew.cmu.edu
        default_domain = andrew.cmu.edu
    }
        CS.CMU.EDU = {
                kdc = kerberos-1.srv.cs.cmu.edu
                kdc = kerberos-2.srv.cs.cmu.edu
                kdc = kerberos-3.srv.cs.cmu.edu
                admin_server = kerberos.cs.cmu.edu
        }
    DEMENTIA.ORG = {
        kdc = kerberos.dementix.org
        kdc = kerberos2.dementix.org
        admin_server = kerberos.dementix.org
    }
    stanford.edu = {
        kdc = krb5auth1.stanford.edu
        kdc = krb5auth2.stanford.edu
        kdc = krb5auth3.stanford.edu
        master_kdc = krb5auth1.stanford.edu
        admin_server = krb5-admin.stanford.edu
        default_domain = stanford.edu
    }
        UTORONTO.CA = {
                kdc = kerberos1.utoronto.ca
                kdc = kerberos2.utoronto.ca
                kdc = kerberos3.utoronto.ca
                admin_server = kerberos1.utoronto.ca
                default_domain = utoronto.ca
    }
[domain_realm]
    .mit.edu = ATHENA.MIT.EDU
    mit.edu = ATHENA.MIT.EDU
    .media.mit.edu = MEDIA-LAB.MIT.EDU
    media.mit.edu = MEDIA-LAB.MIT.EDU
    .csail.mit.edu = CSAIL.MIT.EDU
    csail.mit.edu = CSAIL.MIT.EDU
    .whoi.edu = ATHENA.MIT.EDU
    whoi.edu = ATHENA.MIT.EDU
    .stanford.edu = stanford.edu
    .slac.stanford.edu = SLAC.STANFORD.EDU
        .toronto.edu = UTORONTO.CA
        .utoronto.ca = UTORONTO.CA
        .abc.local = ABC.LOCAL
        abc.local = ABC.LOCAL

nxlog.conf

User nxlog
Group nxlog
Panic Soft

# default values:
define INSTALLDIR /opt/nxlog
# PidFile   %INSTALLDIR%/var/run/nxlog/nxlog.pid
# CacheDir  %INSTALLDIR%/var/spool/nxlog
# ModuleDir %INSTALLDIR%/lib/nxlog/modules
# SpoolDir %INSTALLDIR%/var/spool/nxlog

define CERTDIR %INSTALLDIR%/var/lib/nxlog/cert
define CONFDIR %INSTALLDIR%/etc/nxlog.d

# Note that these two lines define constants only; the log file location
# is ultimately set by the `LogFile` directive (see below). The
# `MYLOGFILE` define is also used to rotate the log file automatically
# (see the `_fileop` block).
define LOGDIR %INSTALLDIR%/var/log/nxlog
define MYLOGFILE %LOGDIR%/nxlog.log

# If you are not using NXLog Manager, disable the `include` line
# and enable LogLevel and LogFile.
#include %CONFDIR%/*.conf
LogLevel    INFO
LogFile     %MYLOGFILE%

<Extension _syslog>
    Module  xm_syslog
</Extension>

# This block rotates `%MYLOGFILE%` on a schedule. Note that if `LogFile`
# is changed in managed.conf via NXLog Manager, rotation of the new
# file should also be configured there.
<Extension _fileop>
    Module  xm_fileop

    # Check the size of our log file hourly, rotate if larger than 5MB
    <Schedule>
        Every   1 hour
        <Exec>
            if ( file_exists('%MYLOGFILE%') and
                 (file_size('%MYLOGFILE%') >= 5M) )
            {
                 file_cycle('%MYLOGFILE%', 8);
            }
        </Exec>
    </Schedule>

    # Rotate our log file every week on Sunday at midnight
    <Schedule>
        When    @weekly
        Exec    if file_exists('%MYLOGFILE%') file_cycle('%MYLOGFILE%', 8);
    </Schedule>
</Extension>

<Input windows_events>
    Module              im_wseventing
    Address             http://linux-wec.abc.local:80/wsman/
    ListenAddr          0.0.0.0
    Port                80
    <QueryXML>
        <QueryList>
            <Query Id="0">
                <Select Path="Application">*</Select>
                <Select Path="Security">*</Select>
                <Select Path="Setup">*</Select>
                <Select Path="System">*</Select>
                <Select Path="ForwardedEvents">*</Select>
                <Select Path="Windows PowerShell">*</Select>
            </Query>
        </QueryList>
    </QueryXML>

    # Log connections for testing and troubleshooting
    LogConnections      TRUE
</Input>

<Output file>
    Module  om_file
    File    "%LOGDIR%/windows.log"
</Output>

<Route uds_to_file>
    Path  windows_events => file
</Route>

补充信息

  • ADSERVER和WEC客户端均加入abc.local域
  • 已为linux-wec配置DNS正向及反向记录
  • 已在ADSERVER的AD用户和计算机中创建linux-wec账户
  • WEC客户端组策略配置:计算机配置>管理模板>Windows组件>事件转发>配置目标订阅管理器已启用,设置值为:
Server=HTTP://linux-wec.abc.local:80/wsman/,Refresh=30

解决方案

错误核心是keytab文件中缺少HTTP/linux-wec.abc.local@ABC.LOCAL的票据,按以下步骤修复:

1. 确认服务主体名称(SPN)配置

在ADSERVER上以域管理员身份执行PowerShell命令,检查linux-wec账户是否绑定正确的SPN:

setspn -L linux-wec

需确保输出包含HTTP/linux-wec.abc.local和HTTP/linux-wec。如果缺失,执行以下命令添加:

setspn -A HTTP/linux-wec.abc.local linux-wec
setspn -A HTTP/linux-wec linux-wec

2. 重新生成keytab文件

在ADSERVER上执行以下命令生成keytab(替换/path/to/save/linux-wec.keytab为实际保存路径):

ktpass /princ HTTP/linux-wec.abc.local@ABC.LOCAL /mapuser linux-wec@ABC.LOCAL /pass * /out /path/to/save/linux-wec.keytab /crypto ALL /ptype KRB5_NT_PRINCIPAL /kvno 7
  • /kvno 7需匹配错误日志中的ticket kvno 7
  • 输入linux-wec账户密码时确保正确

3. 传输keytab到Ubuntu服务器

用scp或其他方式将生成的keytab文件传到linux-wec服务器,建议放在/etc/krb5.keytab路径。

4. 配置nxlog使用keytab

修改nxlog.conf的<Input windows_events>块,添加Kerberos相关配置:

<Input windows_events>
    Module              im_wseventing
    Address             http://linux-wec.abc.local:80/wsman/
    ListenAddr          0.0.0.0
    Port                80
    # 添加Kerberos配置
    Kerberos            TRUE
    KeytabFile          /etc/krb5.keytab  # 替换为你的keytab实际路径
    ServicePrincipalName HTTP/linux-wec.abc.local
    <QueryXML>
        <!-- 原QueryXML内容保持不变 -->
    </QueryXML>
    LogConnections      TRUE
</Input>

5. 设置keytab文件权限

确保nxlog用户能读取keytab文件:

sudo chown nxlog:nxlog /etc/krb5.keytab
sudo chmod 600 /etc/krb5.keytab

6. 验证Kerberos票据

在Ubuntu服务器上执行以下命令验证keytab有效性:

kinit -kt /etc/krb5.keytab HTTP/linux-wec.abc.local@ABC.LOCAL
klist

如果输出包含有效票据,说明keytab配置正确。

7. 重启nxlog服务

sudo systemctl restart nxlog

查看日志确认错误是否消失:

tail -f /opt/nxlog/var/log/nxlog/nxlog.log

额外排查点

  • 确保Ubuntu服务器系统时间与AD服务器同步(Kerberos允许最大5分钟时间差)
  • 检查krb5.conf中default_realm为大写ABC.LOCAL,与AD域一致
  • 确认WEC客户端组策略中的服务器地址与nxlog配置的Address完全匹配(包括大小写、端口)

内容的提问来源于stack exchange,提问作者NTSO

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 15:57:02