<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic auditd logging to syslogd in Operating System - Linux</title>
    <link>https://community.hpe.com/t5/operating-system-linux/auditd-logging-to-syslogd/m-p/4591843#M39932</link>
    <description>hello, &lt;BR /&gt;&lt;BR /&gt;we use a central logger for syslog and take advantage of the @server_name in the syslogd.conf file. we also use the auditd to track files as defined in /etc/audit.rules which is logged to /var/log/audit/audit.log.&lt;BR /&gt;&lt;BR /&gt;our final need is to get the entries of audit.log to the central server. I would think that I can send audit logging (somehow) to syslog. I have found no way to do so that is "proper". i did find that when I have the audit servcice started and I kill the auditd process, the kernel loggs the audit events to syslog. this does not seem proper.&lt;BR /&gt;&lt;BR /&gt;also, the audisp (audit dispatcher), doesn't seem to have come with the audit RPM (it's not  at /sbin/audispd) AND I don't think this is a solution.&lt;BR /&gt;&lt;BR /&gt;please help and suggest or direct how to achieve sending off the audit log entries to syslog (where they go to @server_name) OR another , maybe the correct way to get audit logging to a central server.&lt;BR /&gt;&lt;BR /&gt;thanks</description>
    <pubDate>Fri, 26 Feb 2010 20:48:28 GMT</pubDate>
    <dc:creator>Paul Wasik</dc:creator>
    <dc:date>2010-02-26T20:48:28Z</dc:date>
    <item>
      <title>auditd logging to syslogd</title>
      <link>https://community.hpe.com/t5/operating-system-linux/auditd-logging-to-syslogd/m-p/4591843#M39932</link>
      <description>hello, &lt;BR /&gt;&lt;BR /&gt;we use a central logger for syslog and take advantage of the @server_name in the syslogd.conf file. we also use the auditd to track files as defined in /etc/audit.rules which is logged to /var/log/audit/audit.log.&lt;BR /&gt;&lt;BR /&gt;our final need is to get the entries of audit.log to the central server. I would think that I can send audit logging (somehow) to syslog. I have found no way to do so that is "proper". i did find that when I have the audit servcice started and I kill the auditd process, the kernel loggs the audit events to syslog. this does not seem proper.&lt;BR /&gt;&lt;BR /&gt;also, the audisp (audit dispatcher), doesn't seem to have come with the audit RPM (it's not  at /sbin/audispd) AND I don't think this is a solution.&lt;BR /&gt;&lt;BR /&gt;please help and suggest or direct how to achieve sending off the audit log entries to syslog (where they go to @server_name) OR another , maybe the correct way to get audit logging to a central server.&lt;BR /&gt;&lt;BR /&gt;thanks</description>
      <pubDate>Fri, 26 Feb 2010 20:48:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/auditd-logging-to-syslogd/m-p/4591843#M39932</guid>
      <dc:creator>Paul Wasik</dc:creator>
      <dc:date>2010-02-26T20:48:28Z</dc:date>
    </item>
  </channel>
</rss>

