如何将RHEL/Ubuntu主机的auditd日志推送至远程QRadar服务器
Got it, let's walk through exactly how to get those auditd logs from your Server-2 (whether it's RHEL or Ubuntu) over to QRadar running on Server-1. I'll break this down into distro-specific steps plus the QRadar side setup to make it straightforward:
Prerequisites First
Before diving in, double-check these:
- Server-2 and Server-1 can communicate over the network (no firewall blocks between them on the port you'll use, usually UDP/TCP 514)
- auditd is running and generating logs on Server-2 (confirm with
sudo tail /var/log/audit/audit.log) - QRadar is up and accessible from Server-2
For RHEL-Based Server-2
- Ensure rsyslog is installed and running (it's usually pre-installed, but just to be safe):
sudo dnf install rsyslog -y sudo systemctl enable --now rsyslog - Configure rsyslog to forward auditd logs
Create a dedicated config file for auditd (cleaner than editing the main rsyslog.conf):
Paste these lines (replacesudo nano /etc/rsyslog.d/auditd.conf<Server-1-IP>with your QRadar server's actual IP; use@@instead of@if you want TCP instead of UDP):
Save and exit the editor.$ModLoad imfile $InputFileName /var/log/audit/audit.log $InputFileTag auditd: $InputFileStateFile stat-auditd $InputFileSeverity info $InputFileFacility local6 $InputRunFileMonitor *.* @<Server-1-IP>:514 - Fix SELinux permissions (if enforcing)
If SELinux is enabled on RHEL, you need to let rsyslog read audit logs:sudo setsebool -P rsyslog_read_audit 1 - Restart rsyslog to apply changes
sudo systemctl restart rsyslog - Test the setup
Send a test log to confirm forwarding works:logger -p local6.info "Test auditd log from RHEL Server-2 to QRadar"
For Ubuntu-Based Server-2
The steps are almost identical, with minor package management differences:
- Ensure rsyslog is installed and running:
sudo apt update && sudo apt install rsyslog -y sudo systemctl enable --now rsyslog - Configure rsyslog for auditd forwarding
Create the same dedicated config file:
Paste the same lines as RHEL (replacesudo nano /etc/rsyslog.d/auditd.conf<Server-1-IP>with your QRadar IP):
Save and exit.$ModLoad imfile $InputFileName /var/log/audit/audit.log $InputFileTag auditd: $InputFileStateFile stat-auditd $InputFileSeverity info $InputFileFacility local6 $InputRunFileMonitor *.* @<Server-1-IP>:514 - Adjust firewall rules (if needed)
If ufw is enabled, allow outbound traffic to QRadar's port:sudo ufw allow out 514/udp - Restart rsyslog
sudo systemctl restart rsyslog - Test the setup
logger -p local6.info "Test auditd log from Ubuntu Server-2 to QRadar"
Set Up QRadar to Receive Auditd Logs
Now that Server-2 is sending logs, tell QRadar to listen for them:
- Log into your QRadar console.
- Go to Admin > Log Sources from the top menu.
- Click Add to create a new log source.
- Fill in the details:
- Log Source Type: Select
Linux Audit(or the closest matching auditd option) - Log Source Identifier: Enter Server-2's IP address or hostname
- Protocol Configuration: Choose
UDPorTCP(match what you set in rsyslog), set the port to 514
- Log Source Type: Select
- Click Save and wait 2-3 minutes for QRadar to start processing the logs.
- Verify by going to Log Activity and searching for
auditdor your test log message.
Quick Troubleshooting Tips
- If logs aren't showing up in QRadar: Check firewall rules on both servers, confirm rsyslog is running, and verify the QRadar log source port matches what you configured.
- If SELinux is blocking on RHEL: Use
sudo ausearch -m avc -ts recentto check for denial messages. - For more granular control: You can adjust the
$InputFileSeverityor filter specific auditd events in rsyslog before forwarding.
内容的提问来源于stack exchange,提问作者anish anil
相关产品推荐
相关产品推荐

