LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Enterprise Linux Forums > Linux - Enterprise
User Name
Password
Linux - Enterprise This forum is for all items relating to using Linux in the Enterprise.

Notices


Reply
  Search this Thread
Old 08-05-2016, 12:08 PM   #1
JockVSJock
Senior Member
 
Registered: Jan 2004
Posts: 1,420
Blog Entries: 4

Rep: Reputation: 164Reputation: 164
What are you logging on a syslog server?


Have a RHEL server where all Oracle databases place the .aud and .dmp files their on a daily basis for safe keeping/audit.

I would like to expand what is backed up/audited to this server and was wondering what others have logged to a syslog server?

thanks
 
Old 08-08-2016, 09:48 AM   #2
ihaveavirus
LQ Newbie
 
Registered: Jul 2016
Distribution: RHEL
Posts: 22

Rep: Reputation: Disabled
At the bare minimum you should log:

logins, sudo, messages, and SELinux violations

If you want to get a little more advanced I suggest looking into AIDE, since it will let you know when just about anything changes on your server including config files, new users, etc. I don't know how well it scales, since we're using it but haven't integrated it into our logging server since we're working on moving away from Spunk to ELK stack.

Last edited by ihaveavirus; 08-08-2016 at 09:49 AM.
 
1 members found this post helpful.
Old 08-08-2016, 11:44 AM   #3
JockVSJock
Senior Member
 
Registered: Jan 2004
Posts: 1,420

Original Poster
Blog Entries: 4

Rep: Reputation: 164Reputation: 164
Thanks for the response.

Right now I have all of my RHEL servers using rsyslog reporting back to this logging server. I will have research on how to setup to log what you recommend, or maybe rsyslog can be setup for this.

Splunk and Elastic Search was recommended by others to review the logs.
 
Old 08-08-2016, 12:28 PM   #4
ihaveavirus
LQ Newbie
 
Registered: Jul 2016
Distribution: RHEL
Posts: 22

Rep: Reputation: Disabled
You are very welcome. If you're in a DoD environment you're going to have to install AIDE anyways, so you may as well become familiar with it:

https://access.redhat.com/solutions/55021

http://aide.sourceforge.net/

You can definitely increase the output from rsyslog and fine tune to get specific messages. Also, when you start getting into logging, remember that space will be utilized very quickly, so its not a good idea to just "fire and forget". Logging servers require continuous maintenance and fine tuning to get the results you need for any given requirements.
 
Old 08-10-2016, 01:51 PM   #5
JockVSJock
Senior Member
 
Registered: Jan 2004
Posts: 1,420

Original Poster
Blog Entries: 4

Rep: Reputation: 164Reputation: 164
AIDE, is something I want to look into as well. However we have Varonis installed, so I'm wondering if I will need both?

The reason I ask is because of the external audits that we have from time to time. I want to set something up in advance, that way when the day comes, I can show the auditors that yes I am auditing various events on the servers.

thanks
 
Old 08-11-2016, 07:11 AM   #6
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Oracle transaction logs?
 
Old 08-11-2016, 07:47 AM   #7
JockVSJock
Senior Member
 
Registered: Jan 2004
Posts: 1,420

Original Poster
Blog Entries: 4

Rep: Reputation: 164Reputation: 164
Quote:
Originally Posted by Habitual View Post
Oracle transaction logs?
Correct, Oracle transactions logs cannot be left on the Oracle Server which generated them. Has to be stored elsewhere, encrypted.
 
Old 08-11-2016, 10:04 AM   #8
ihaveavirus
LQ Newbie
 
Registered: Jul 2016
Distribution: RHEL
Posts: 22

Rep: Reputation: Disabled
Ooo..Varonis looks like a neat utility and is definitely more advanced than AIDE. AIDE monitors for integrity, but it doesn't actively notify you or prevent any data loss or data exfiltration; you have to manually review the data.
 
  


Reply

Tags
backup, syslog



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[syslog-ng] logging remote server by IP address noir911 Linux - Server 4 06-22-2018 08:01 AM
[SOLVED] syslog remote logging with rsyslog server Chenchu Linux - Newbie 3 09-17-2011 01:34 PM
syslog-ng -> syslog-ng logging, how to troubleshoot sir-lancealot Linux - Server 1 01-24-2009 06:07 AM
logging to a remote syslog server is dropping packets draeician73 Linux - Security 1 10-20-2004 06:19 PM
logging and reporting on multiple firewalls to a syslog server cyph3r7 Linux - Security 2 04-13-2004 04:16 PM

LinuxQuestions.org > Forums > Enterprise Linux Forums > Linux - Enterprise

All times are GMT -5. The time now is 07:26 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration