{"id":3158,"date":"2020-06-16T16:22:32","date_gmt":"2020-06-16T07:22:32","guid":{"rendered":"https:\/\/www.secuavail.com\/product\/logstarecollector\/kb\/?p=3158"},"modified":"2024-08-26T15:43:56","modified_gmt":"2024-08-26T06:43:56","slug":"tb-200623_01","status":"publish","type":"post","link":"https:\/\/www.secuavail.com\/kb\/tech-blog\/tb-200623_01\/","title":{"rendered":"Audit.log\u3092syslog\u3092\u5229\u7528\u3057\u3066\u53ce\u96c6\u3059\u308b\u65b9\u6cd5"},"content":{"rendered":"<p>\u5f53\u8a18\u4e8b\u3067\u306f\u3001rsyslog\u3092\u5229\u7528\u3057\u3066Audit.log\u3092syslog\u30b5\u30fc\u30d0\u3067\u3042\u308bLogStare Collector (\u4ee5\u4e0b : LSC\u3068\u8a18\u8f09\u3057\u307e\u3059) \u306b\u3066\u53ce\u96c6\u3059\u308b\u65b9\u6cd5\u3092\u8a18\u8f09\u3057\u307e\u3059\u3002\u203b\u74b0\u5883\u306fCentOS7.7\u3067\u3059\u3002<\/p>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_83 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\"><p class=\"ez-toc-title\" style=\"cursor:inherit\">\u76ee\u6b21<\/p>\n<\/div><nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/www.secuavail.com\/kb\/tech-blog\/tb-200623_01\/#%E6%9B%B4%E6%96%B0%E5%B1%A5%E6%AD%B4\" >\u66f4\u65b0\u5c65\u6b74<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/www.secuavail.com\/kb\/tech-blog\/tb-200623_01\/#%E4%BA%8B%E5%89%8D%E6%BA%96%E5%82%99\" >\u4e8b\u524d\u6e96\u5099<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/www.secuavail.com\/kb\/tech-blog\/tb-200623_01\/#%E8%A8%AD%E5%AE%9A%E5%86%85%E5%AE%B9Linux%E5%81%B4\" >\u8a2d\u5b9a\u5185\u5bb9(Linux\u5074)<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/www.secuavail.com\/kb\/tech-blog\/tb-200623_01\/#%E8%A8%AD%E5%AE%9A%E5%86%85%E5%AE%B9LSC%E5%81%B4\" >\u8a2d\u5b9a\u5185\u5bb9(LSC\u5074)<\/a><\/li><\/ul><\/nav><\/div>\n<h2><span class=\"ez-toc-section\" id=\"%E6%9B%B4%E6%96%B0%E5%B1%A5%E6%AD%B4\"><\/span>\u66f4\u65b0\u5c65\u6b74<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>2020\/06\/16 \u65b0\u898f\u516c\u958b\u3057\u307e\u3057\u305f\u3002<br \/>\n2023\/10\/10 rsyslog.conf\u306e\u8a18\u8f09\u5185\u5bb9\u3092\u4e00\u90e8\u4fee\u6b63\u3057\u307e\u3057\u305f\u3002<\/p>\n<h2><span class=\"ez-toc-section\" id=\"%E4%BA%8B%E5%89%8D%E6%BA%96%E5%82%99\"><\/span>\u4e8b\u524d\u6e96\u5099<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<ul style=\"list-style-type: disc;\">\n<li>LSC\u30b5\u30fc\u30d0\u306eIP \u30a2\u30c9\u30ec\u30b9\u3092\u30c1\u30a7\u30c3\u30af\u3057\u307e\u3059\u3002(syslog \u306e\u8ee2\u9001\u5148\u3068\u3057\u3066\u8a2d\u5b9a\u3044\u305f\u3057\u307e\u3059\u3002)<br \/>\n<span style=\"font-size: 10pt;\">\u203b\u5f53\u8a18\u4e8b\u3067\u306f\u3001172.23.61.59 \u3092LSC \u30b5\u30fc\u30d0\u3001172.23.61.50\u3092Linux\u30b5\u30fc\u30d0\u3068\u3057\u3066\u6271\u3044\u307e\u3059\u3002<\/span><\/li>\n<\/ul>\n<h2><span class=\"ez-toc-section\" id=\"%E8%A8%AD%E5%AE%9A%E5%86%85%E5%AE%B9Linux%E5%81%B4\"><\/span>\u8a2d\u5b9a\u5185\u5bb9(Linux\u5074)<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<ul style=\"list-style-type: disc;\">\n<li>\/etc\/audisp\/plugins.d\/syslog.conf\u3092\u7de8\u96c6\u3057\u307e\u3059\u3002\u672c\u8a18\u4e8b\u3067\u306fAudit.log\u306e\u30d5\u30a1\u30b7\u30ea\u30c6\u30a3\u3068\u3057\u3066local5\u3092\u9078\u629e\u3057\u307e\u3059\u3002<\/li>\n<\/ul>\n<p>\u5909\u66f4\u524d<\/p>\n<pre class=\"lang:default highlight:0 decode:true\"># vi \/etc\/audisp\/plugins.d\/syslog.conf\r\nactive = no\r\ndirection = out\r\npath = builtin_syslog\r\ntype = builtin\r\nargs = LOG_INFO\r\nformat = string<\/pre>\n<p>\u5909\u66f4\u5f8c<\/p>\n<pre class=\"lang:default highlight:0 decode:true \"># vi \/etc\/audisp\/plugins.d\/syslog.conf\r\nactive = yes\r\ndirection = out\r\npath = builtin_syslog\r\ntype = builtin\r\nargs = LOG_LOCAL5\r\nformat = string<\/pre>\n<ul style=\"list-style-type: disc;\">\n<li>\/etc\/rsyslog.conf\u3092\u7de8\u96c6\u3057\u307e\u3059\u3002\u672c\u8a18\u4e8b\u3067\u306f\u3001\u30ed\u30fc\u30ab\u30eb\u306bAudit.log\u3092\u6b8b\u3055\u306a\u3044\u8a2d\u5b9a\u3092\u884c\u3044\u307e\u3059\u3002<br \/>\n\u203b\u30ed\u30fc\u30ab\u30eb\u306bAudit.log\u3092\u6b8b\u3059\u5834\u5408\u3001\u300cloca5.none\u300d\u3068\u3044\u3046\u8a18\u8ff0\u306f\u884c\u308f\u306a\u3044\u3067\u304f\u3060\u3055\u3044\u3002<\/li>\n<\/ul>\n<pre class=\"lang:default highlight:0 decode:true \"># vi \/etc\/rsyslog.conf\r\n\uff5e\uff5e\u7701\u7565\uff5e\uff5e\r\n# Log anything (except mail) of level info or higher.\r\n# Don't log private authentication messages!\r\n#\u4ee5\u4e0b\u306b\u6587\u8a00\u3092\u8ffd\u8a18#\r\n*.info;mail.none;authpriv.none;cron.none;local5.none                \/var\/log\/messages\r\n\uff5e\uff5e\u7701\u7565\uff5e\uff5e\r\n# remote host is: name\/ip:port, e.g. 192.168.0.1:514, port optional\r\n#*.* @@remote-host:514\r\n#\u4ee5\u4e0b\u306b\u6587\u8a00\u3092\u8ffd\u8a18#\r\nlocal5.* @@172.23.61.59<\/pre>\n<ul style=\"list-style-type: disc;\">\n<li>\u30b5\u30fc\u30d3\u30b9\u3092\u518d\u8d77\u52d5\u3057\u307e\u3059\u3002<\/li>\n<\/ul>\n<pre class=\"lang:default highlight:0 decode:true \"># service auditd restart\r\n# service rsyslog restart<\/pre>\n<p>\u4ee5\u4e0a\u3067\u3001LSC\u30b5\u30fc\u30d0\u306bAudit.log\u304c\u9001\u4fe1\u3055\u308c\u307e\u3059\u3002<\/p>\n<h2><span class=\"ez-toc-section\" id=\"%E8%A8%AD%E5%AE%9A%E5%86%85%E5%AE%B9LSC%E5%81%B4\"><\/span>\u8a2d\u5b9a\u5185\u5bb9(LSC\u5074)<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<ul style=\"list-style-type: disc;\">\n<li>LSC\u306b\u3066\u5de6\u5074\u306e\u30b9\u30d1\u30ca\u30de\u30fc\u30af\u3092\u30af\u30ea\u30c3\u30af\u3057\u76e3\u8996\u30fb\u30ed\u30b0\u53ce\u96c6\u8a2d\u5b9a\u3092\u958b\u304d\u307e\u3059\u3002<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3174\" src=\"\/kb\/wp-content\/uploads\/2020\/06\/52b1403278457da8f8505e2f4f6f6086.png\" alt=\"\" width=\"436\" height=\"265\" \/><\/p>\n<ul style=\"list-style-type: disc;\">\n<li>\u30c7\u30d0\u30a4\u30b9\u30fb\u30b0\u30eb\u30fc\u30d7\u3088\u308a\u65b0\u898f\u30c7\u30d0\u30a4\u30b9\u3092\u8ffd\u52a0\u3057\u307e\u3059\u3002<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3178\" src=\"\/kb\/wp-content\/uploads\/2020\/06\/a0e637c833c8616a591dcd7d793dd227.png\" alt=\"\" width=\"622\" height=\"550\" \/><\/p>\n<ul style=\"list-style-type: disc;\">\n<li>\u76e3\u8996\u30fb\u53ce\u96c6\u3088\u308a\u5148\u7a0b\u8ffd\u52a0\u3057\u305f\u30c7\u30d0\u30a4\u30b9\u3092\u9078\u629e\u3057\u3066\u3001syslog\u53ce\u96c6\u3092\u9078\u629e\u3057\u307e\u3059\u3002\u30d5\u30a1\u30b7\u30ea\u30c6\u30a3\u3068\u3057\u3066local5\u3001\u30d7\u30e9\u30a4\u30aa\u30ea\u30c6\u30a3\u3068\u3057\u3066info\u3092\u6307\u5b9a\u3057\u3066\u3044\u307e\u3059\u3002<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4242\" src=\"https:\/\/www.secuavail.com\/kb\/wp-content\/uploads\/2020\/08\/0d40a5e4a645fc6b96e767d64ac0878e.png\" alt=\"\" width=\"560\" height=\"281\" srcset=\"https:\/\/www.secuavail.com\/kb\/wp-content\/uploads\/2020\/08\/0d40a5e4a645fc6b96e767d64ac0878e.png 560w, https:\/\/www.secuavail.com\/kb\/wp-content\/uploads\/2020\/08\/0d40a5e4a645fc6b96e767d64ac0878e-300x151.png 300w\" sizes=\"auto, (max-width: 560px) 100vw, 560px\" \/><\/p>\n<p>\u4e0a\u8a18\u8a2d\u5b9a\u306b\u3066LSC\u3067Audit.log\u3092\u53ce\u96c6\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"\u5f53\u8a18\u4e8b\u3067\u306f\u3001rsyslog\u3092\u5229\u7528\u3057\u3066Audit.log\u3092syslog\u30b5\u30fc\u30d0\u3067\u3042\u308bLogStare Collector (\u4ee5\u4e0b : LSC\u3068\u8a18\u8f09\u3057\u307e\u3059) \u306b\u3066\u53ce\u96c6\u3059\u308b\u65b9\u6cd5\u3092\u8a18\u8f09\u3057\u307e\u3059\u3002\u203b\u74b0\u5883\u306fCentOS7.7\u3067\u3059\u3002 \u66f4\u65b0 [&hellip;]","protected":false},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[50,2],"tags":[9,17],"class_list":["post-3158","post","type-post","status-publish","format-standard","hentry","category-windows-linux","category-tech-blog","tag-linux","tag-lscconf"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.secuavail.com\/kb\/wp-json\/wp\/v2\/posts\/3158","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.secuavail.com\/kb\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.secuavail.com\/kb\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.secuavail.com\/kb\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.secuavail.com\/kb\/wp-json\/wp\/v2\/comments?post=3158"}],"version-history":[{"count":44,"href":"https:\/\/www.secuavail.com\/kb\/wp-json\/wp\/v2\/posts\/3158\/revisions"}],"predecessor-version":[{"id":14261,"href":"https:\/\/www.secuavail.com\/kb\/wp-json\/wp\/v2\/posts\/3158\/revisions\/14261"}],"wp:attachment":[{"href":"https:\/\/www.secuavail.com\/kb\/wp-json\/wp\/v2\/media?parent=3158"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.secuavail.com\/kb\/wp-json\/wp\/v2\/categories?post=3158"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.secuavail.com\/kb\/wp-json\/wp\/v2\/tags?post=3158"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}