central log-server with auditdisp

Posted by johan on Server Fault See other posts from Server Fault or by johan
Published on 2012-10-26T10:15:08Z Indexed on 2012/10/26 11:03 UTC
Read the original article Hit count: 256

Filed under:
|
|
|

I want to setup a central log-server. The log-server is running with debian 6.0.6 and the audit daemon is installed in version 1.7.13-1.

The Clients are running with Red Hat 5.5 and they connect to the log-server via audispd. The connection works fine and i get all messages from each node.

My questions is: is it possible that the auditd daemon from the log server write the messages from each node in a separate file?

I try to transfer the messages via the syslog daemon, that works but i can not use tools like ausearch to analyze these log-files.

© Server Fault or respective owner

Related posts about linux

Related posts about logging