You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将RHEL/Ubuntu主机的auditd日志推送至远程QRadar服务器

Got it, let's walk through exactly how to get those auditd logs from your Server-2 (whether it's RHEL or Ubuntu) over to QRadar running on Server-1. I'll break this down into distro-specific steps plus the QRadar side setup to make it straightforward:

Prerequisites First

Before diving in, double-check these:

  • Server-2 and Server-1 can communicate over the network (no firewall blocks between them on the port you'll use, usually UDP/TCP 514)
  • auditd is running and generating logs on Server-2 (confirm with sudo tail /var/log/audit/audit.log)
  • QRadar is up and accessible from Server-2

For RHEL-Based Server-2

  1. Ensure rsyslog is installed and running (it's usually pre-installed, but just to be safe):
    sudo dnf install rsyslog -y
    sudo systemctl enable --now rsyslog
    
  2. Configure rsyslog to forward auditd logs
    Create a dedicated config file for auditd (cleaner than editing the main rsyslog.conf):
    sudo nano /etc/rsyslog.d/auditd.conf
    
    Paste these lines (replace <Server-1-IP> with your QRadar server's actual IP; use @@ instead of @ if you want TCP instead of UDP):
    $ModLoad imfile
    $InputFileName /var/log/audit/audit.log
    $InputFileTag auditd:
    $InputFileStateFile stat-auditd
    $InputFileSeverity info
    $InputFileFacility local6
    $InputRunFileMonitor
    *.* @<Server-1-IP>:514
    
    Save and exit the editor.
  3. Fix SELinux permissions (if enforcing)
    If SELinux is enabled on RHEL, you need to let rsyslog read audit logs:
    sudo setsebool -P rsyslog_read_audit 1
    
  4. Restart rsyslog to apply changes
    sudo systemctl restart rsyslog
    
  5. Test the setup
    Send a test log to confirm forwarding works:
    logger -p local6.info "Test auditd log from RHEL Server-2 to QRadar"
    

For Ubuntu-Based Server-2

The steps are almost identical, with minor package management differences:

  1. Ensure rsyslog is installed and running:
    sudo apt update && sudo apt install rsyslog -y
    sudo systemctl enable --now rsyslog
    
  2. Configure rsyslog for auditd forwarding
    Create the same dedicated config file:
    sudo nano /etc/rsyslog.d/auditd.conf
    
    Paste the same lines as RHEL (replace <Server-1-IP> with your QRadar IP):
    $ModLoad imfile
    $InputFileName /var/log/audit/audit.log
    $InputFileTag auditd:
    $InputFileStateFile stat-auditd
    $InputFileSeverity info
    $InputFileFacility local6
    $InputRunFileMonitor
    *.* @<Server-1-IP>:514
    
    Save and exit.
  3. Adjust firewall rules (if needed)
    If ufw is enabled, allow outbound traffic to QRadar's port:
    sudo ufw allow out 514/udp
    
  4. Restart rsyslog
    sudo systemctl restart rsyslog
    
  5. Test the setup
    logger -p local6.info "Test auditd log from Ubuntu Server-2 to QRadar"
    

Set Up QRadar to Receive Auditd Logs

Now that Server-2 is sending logs, tell QRadar to listen for them:

  1. Log into your QRadar console.
  2. Go to Admin > Log Sources from the top menu.
  3. Click Add to create a new log source.
  4. Fill in the details:
    • Log Source Type: Select Linux Audit (or the closest matching auditd option)
    • Log Source Identifier: Enter Server-2's IP address or hostname
    • Protocol Configuration: Choose UDP or TCP (match what you set in rsyslog), set the port to 514
  5. Click Save and wait 2-3 minutes for QRadar to start processing the logs.
  6. Verify by going to Log Activity and searching for auditd or your test log message.

Quick Troubleshooting Tips
  • If logs aren't showing up in QRadar: Check firewall rules on both servers, confirm rsyslog is running, and verify the QRadar log source port matches what you configured.
  • If SELinux is blocking on RHEL: Use sudo ausearch -m avc -ts recent to check for denial messages.
  • For more granular control: You can adjust the $InputFileSeverity or filter specific auditd events in rsyslog before forwarding.

内容的提问来源于stack exchange,提问作者anish anil

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 09:51:09