Remotely logging audit rules.

Stephen J. Smoogen smooge at gmail.com
Tue Nov 1 23:31:01 UTC 2005


I got a development request to see how much work it would take to do.
Our policy wags want to have all object audit events (or whatever the
real term for that is...)  to be sent both locally and remotely. The
reason is a supposed policy for checking the local logs against remote
logs to see if they have been tampered with and for being able to
train a SIM to look for events in the centralized logs.

My 5000 foot question is how would the best way to implement this be?
For the current RHEL 4 I would probably need some sort of tail -f xxx
| logger type script.


--
Stephen J Smoogen.
CSIRT/Linux System Administrator




More information about the Linux-audit mailing list