You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Rsyslog TLS配置启用后TCP 6514端口无法监听的问题求助

Rsyslog TLS配置启用后TCP 6514端口无法监听的问题求助

概述

我有一台接收外部客户端Syslog数据的服务器,但没有这些客户端的管理权限。目标是通过在TCP 6514端口上实现Syslog的TLS加密,将现有配置迁移到传输中数据加密。所有网络、防火墙规则和SELinux配置都已验证,并且我已成功测试通过TCP 6514端口接收未加密的Syslog消息。我还下载了rsyslog-gnutls作为TLS驱动。

Syslog服务器详情

$ cat /etc/os-release
NAME="CentOS Linux"
VERSION="7 (Core)"

$ rsyslogd -v
rsyslogd 8.24.0-57.el7_9.3, compiled with:
PLATFORM:                               x86_64-redhat-linux-gnu
PLATFORM (lsb_release -d):
FEATURE_REGEXP:                         Yes
GSSAPI Kerberos 5 support:              Yes
FEATURE_DEBUG (debug build, slow code): No
32bit Atomic operations supported:      Yes
64bit Atomic operations supported:      Yes
memory allocator:                       system default
Runtime Instrumentation (slow code):    No
uuid support:                           Yes
Number of Bits in RainerScript integers: 64

$ yum list installed | grep rsyslog-gnutls
rsyslog-gnutls.x86_64              8.24.0-57.el7_9.3

基础Syslog配置(/etc/rsyslog.conf)

这部分从之前TCP 514端口的未加密工作配置保留未修改,这里完整列出作为参考:

# rsyslog configuration file
# For more information see /usr/share/doc/rsyslog-*/rsyslog_conf.html
# If you experience problems, see http://www.rsyslog.com/doc/troubleshoot.html

#### MODULES ####

# The imjournal module bellow is now used as a message source instead of imuxsock.
$ModLoad imuxsock # provides support for local system logging (e.g. via logger command)
$ModLoad imjournal # provides access to the systemd journal
#$ModLoad imklog # reads kernel messages (the same are read from journald)
#$ModLoad immark  # provides --MARK-- message capability

# Provides UDP syslog reception
#$ModLoad imudp
#$UDPServerRun 514

# Provides TCP syslog reception
#$ModLoad imtcp
#$InputTCPServerRun 514

#### GLOBAL DIRECTIVES ####

# Where to place auxiliary files
$WorkDirectory /var/lib/rsyslog

# Use default timestamp format
$ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat

# File syncing capability is disabled by default. This feature is usually not required,
# not useful and an extreme performance hit
#$ActionFileEnableSync on

# Include all config files in /etc/rsyslog.d/
$IncludeConfig /etc/rsyslog.d/*.conf

# Turn off message reception via local log socket;
# local messages are retrieved through imjournal now.
$OmitLocalLogging on

# File to store the position in the journal
$IMJournalStateFile imjournal.state

$FileCreateMode 0640

#### RULES ####

# Log all kernel messages to the console.
# Logging much else clutters up the screen.
#kern.*                                                 /dev/console

# Log anything (except mail) of level info or higher.
# Don't log private authentication messages!
#*.info;mail.none;authpriv.none;cron.none                /var/log/messages
*.*                                                     /var/log/messages

# The authpriv file has restricted access.
authpriv.*                                              /var/log/secure

# Log all the mail messages in one place.
mail.*                                                  -/var/log/maillog

# Log all user comands
local3.*                                                /var/log/userCommands.log

# Log cron stuff
cron.*                                                  /var/log/cron

# Everybody gets emergency messages
*.emerg                                                 :omusrmsg:*

# Save news errors of level crit and higher in a special file.
uucp,news.crit                                          /var/log/spooler

# Save boot messages also to boot.log
local7.*                                                /var/log/boot.log

自定义包含配置(/etc/rsyslog.d/syslog-tls.conf)

这是我创建的自定义配置文件。下面的配置显示了当前在TCP 6514端口上未加密的工作状态。这是/etc/rsyslog.d目录中唯一的.conf文件,所以不会导入其他配置。之前有三个其他.conf文件,我已经重命名为.conf.bak,所以我认为rsyslogd不会读取这些文件,因为扩展名改变了:

########################################################################
#
# This file is included from /etc/rsyslog.conf as long as it is located
# in /etc/rsyslog.d/.
#
########################################################################

$umask 0000     #not supported in global() for rsyslog versions < 8.26
global(
preserveFQDN="on"
parser.escapeControlCharactersOnReceive="off"   #Prevent escaping of new lines
#defaultNetstreamDriver="gtls"
#defaultNetstreamDriverCAFile="/etc/rsyslog.d/certs/myCertAuthCertificate.pem"
#defaultNetstreamDriverCertFile="/etc/rsyslog.d/certs/mySyslogUfServerChainedCertificate.pem"
#defaultNetstreamDriverKeyFile="/etc/rsyslog.d/certs/mySyslogUfServerPrivKey.key"
)

module(
load="imtcp"
maxSessions="500"
disableLFDelimiter="off"
#streamDriver.Name="gtls"
#streamDriver.Mode="1"
#streamDriver.Authmode="x509/certvalid"
#streamDriver.PermittedPeers="172.16.32.155"
)

module(
load="builtin:omfile"
dirCreateMode="0750"
dirOwner="splunk"
dirGroup="splunk"
fileCreateMode="0640"
fileOwner="splunk"
fileGroup="splunk"
)

template(name="foo_test" type="string" string="/var/log/foo_test/%HOSTNAME%/%$year%_%$month%_%$day%.log")

ruleset(name="foo"){
if ($fromhost-ip != '127.0.0.1') then
action(type="omfile" dynaFile="foo_test")
stop
}

input(type="imtcp" port="6514")

问题描述

如果我取消syslog-tcp.conf中与TLS相关的配置参数(DefaultNetstreamDriver和StreamDriver)的注释并重启rsyslog,TCP 6514端口不再出现在netstat中。这说明我选择的配置参数和/或定义的顺序有问题。

对配置文件运行语法验证检查显示没有问题,但根据我的研究,这仅表示语法正确,运行时仍可能存在问题。

相关命令输出:

$ sudo systemctl restart rsyslog
$ sudo systemctl status rsyslog
● rsyslog.service - System Logging Service
Loaded: loaded (/usr/lib/systemd/system/rsyslog.service; enabled; vendor preset: enabled)
Active: active (running) since Wed 2023-08-09 18:46:52 GMT; 3s ago
Docs: man:rsyslogd(8)
http://www.rsyslog.com/doc/
Main PID: 22327 (rsyslogd)
CGroup: /system.slice/rsyslog.service
└─22327 /usr/sbin/rsyslogd -n

Aug 09 18:46:52 testbox01 systemd[1]: Starting System Logging Service...
Aug 09 18:46:52 testbox01 systemd[1]: Started System Logging Service.

$ rsyslogd -f /etc/rsyslog.conf -N1
rsyslogd: version 8.24.0-57.el7_9.3, config validation run (level 1), master config /etc/rsyslog.conf
rsyslogd: End of config validation run. Bye.

$ rsyslogd -f /etc/rsyslog.d/syslog-tls.conf -N3
rsyslogd: version 8.24.0-57.el7_9.3, config validation run (level 3), master config /etc/rsyslog.d/syslog-tls.conf
rsyslogd: End of config validation run. Bye.

这是我第一次尝试配置带TLS的rsyslog,在此之前我对rsyslog也没有太多经验。希望熟悉rsyslog的大佬能帮我指出问题所在,提前感谢!

更新记录

8/9/23

我以调试模式运行rsyslogd,得到了大量输出。下面是我认为与问题相关的截断版本,如果需要可以提供更多输出。我注意到当rsyslogd以前台调试模式运行时,TCP 6514端口会作为监听端口出现。一旦我终止调试模式并以正常方式重启rsyslogd,TCP 6514端口就会保持关闭状态,即不会出现在netstat的LISTEN状态中。

调试输出片段:

3144.701090845:main thread    : imtcp: trying to add port *:6514
3144.701096552:main thread    : ratelimit:tcperver:new ratelimiter:bReduceRepeatMsgs 0
3144.701103144:main thread    : caller requested object 'nsd_gtls', not found (iRet -3003)
3144.701107289:main thread    : Requested to load module 'lmnsd_gtls'
3144.701112377:main thread    : loading module '/usr/lib64/rsyslog/lmnsd_gtls.so'
3144.704593252:main thread    : source file nsd_gtls.c requested reference for module 'lmnet', reference count now 6
3144.704601962:main thread    : caller requested object 'nsd_ptcp', not found (iRet -3003)
3144.704606370:main thread    : Requested to load module 'lmnsd_ptcp'
3144.704613121:main thread    : loading module '/usr/lib64/rsyslog/lmnsd_ptcp.so'
3144.704740556:main thread    : source file nsd_ptcp.c requested reference for module 'lmnetstrms', reference count now 4
3144.704750825:main thread    : module lmnsd_ptcp of type 2 being loaded (keepType=0).
3144.704754868:main thread    : entry point 'isCompatibleWithFeature' not present in module
3144.704758844:main thread    : entry point 'setModCnf' not present in module
3144.704762675:main thread    : entry point 'getModCnfName' not present in module
3144.704766304:main thread    : entry point 'beginCnfLoad' not present in module
3144.704770744:main thread    : source file nsd_gtls.c requested reference for module 'lmnsd_ptcp', reference count now 1
3144.704785499:main thread    : GTLS CA file: '/etc/rsyslog.d/certs/myCertAuthCertificate.pem'
3144.705337400:main thread    : source file nsdsel_gtls.c requested reference for module 'lmnsd_ptcp', reference count now 2
3144.705344715:main thread    : module lmnsd_gtls of type 2 being loaded (keepType=1).
3144.705348930:main thread    : entry point 'isCompatibleWithFeature' not present in module
3144.705352660:main thread    : entry point 'setModCnf' not present in module
3144.705356421:main thread    : entry point 'getModCnfName' not present in module
3144.705360038:main thread    : entry point 'beginCnfLoad' not present in module
3144.705365118:main thread    : source file netstrms.c requested reference for module 'lmnsd_gtls', reference count now 1
3144.705373376:main thread    : GTLS certificate file: '/etc/rsyslog.d/certs/mySyslogUfServerChainedCertificate.pem'
3144.705377299:main thread    : GTLS key file: '/etc/rsyslog.d/certs/mySyslogUfServerPrivKey.key'
3144.716630033:main thread    : creating tcp listen socket on port 6514
3144.723178541:main thread    : We could initialize 1 TCP listen sockets out of 2 we received - this may or may not be an error indication.
3144.723190317:main thread    : Allocating buffer for 500 TCP sessions.
3144.723201696:main thread    : telling modules to activate config 0x55b2e2beaa20
3144.723206050:main thread    : activating config 0x55b2e2beaa20 for module builtin:omfile
3144.723210213:main thread    : activating config 0x55b2e2beaa20 for module builtin:ompipe
3144.723214794:main thread    : activating config 0x55b2e2beaa20 for module builtin:omfwd
3144.723219318:main thread    : activating config 0x55b2e2beaa20 for module imuxsock
3144.723223556:main thread    : activating config 0x55b2e2beaa20 for module imjournal
3144.723227739:main thread    : activating config 0x55b2e2beaa20 for module imtcp
3144.724453266:main thread    : Allowed TCP Senders:
3144.724459171:main thread    :         No restrictions set.
3144.724465166:main thread    : iterateAllActions calling into action 0x55b2e2c03ec0
3144.724472897:main thread    : action 1 queue: starting queue

8/10/23

我在/etc/sysconfig/rsyslog中添加了SYSLOGD_OPTIONS="-d"选项,如下所示。这里有个疑问:这个选项从rsyslog v3开始就被弃用了,加上它会不会导致无法按照文件注释中指定的兼容模式运行?

# Options for rsyslogd
# Syslogd options are deprecated since rsyslog v3.
# If you want to use them, switch to compatibility mode 2 by "-c 2"
# See rsyslogd(8) for more details
SYSLOGD_OPTIONS="-d"

现在我在rsyslog启动时看到了错误消息:

$ sudo systemctl status rsyslog
● rsyslog.service - System Logging Service
Loaded: loaded (/usr/lib/systemd/system/rsyslog.service; enabled; vendor preset: enabled)
Active: active (running) since Thu 2023-08-10 13:21:36 GMT; 6s ago
Docs: man:rsyslogd(8)
http://www.rsyslog.com/doc/
Main PID: 9362 (rsyslogd)
CGroup: /system.slice/rsyslog.service
└─9362 /usr/sbin/rsyslogd -n -d

Aug 10 13:21:36 testbox01 systemd[1]: Starting System Logging Service...
Aug 10 13:21:36 testbox01 rsyslogd[9362]:  [origin software="rsyslogd" swVersion="8.24.0-57.el7_9.3" x-pid="9362" x-info="http://www.rsyslog.com"] start
Aug
相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.22 12:25:27