You can configure the publication of events in CEF format to an external SIEM system, as well as save the events locally in log files on the server. If you do not need to save events locally, skip steps 4, 6, 7 of the instructions in this section.
Follow the steps below on each cluster node whose events you want to publish to a SIEM system. Only enable the export of events in CEF format after configuring event publishing.
To configure the publication of application events to a SIEM system:
$ActionQueueFileName ForwardToSIEM
$ActionQueueMaxDiskSpace 1g
$ActionQueueSaveOnShutdown on
$ActionQueueType LinkedList
$ActionResumeRetryCount -1
local2.* @<IP address of the SIEM system>:<port used by the SIEM system to receive messages from Syslog over UDP>
If you want to send events over TCP, add the following line:
local2.* @<IP address of the SIEM system>:<port used by the SIEM system to receive messages from Syslog over TCP>
local2.* -/var/log/ksmg-cef-messages
local2.* stop
Example configuration file for exporting over UDP without saving to the local log: $ActionQueueFileName ForwardToSIEM2 $ActionQueueMaxDiskSpace 1g $ActionQueueSaveOnShutdown on $ActionQueueType LinkedList $ActionResumeRetryCount -1 local2.* @10.16.32.64:514 local2.* stop Example configuration file for exporting over TCP with saving to the local log: $ActionQueueFileName ForwardToSIEM2 $ActionQueueMaxDiskSpace 1g $ActionQueueSaveOnShutdown on $ActionQueueType LinkedList $ActionResumeRetryCount -1 local2.* @10.16.32.64:514 local2.* -/var/log/ksmg-cef-messages local2.* stop |
touch /var/log/ksmg-cef-messages
chown root:klusers /var/log/ksmg-cef-messages
chmod 640 /var/log/ksmg-cef-messages
/var/log/ksmg-cef-messages
{
size 500M
rotate 10
compress
missingok
notifempty
sharedscripts
postrotate
/usr/bin/systemctl kill -s HUP rsyslog.service >/dev/null 2>&1 || true
endscript
}
systemctl restart rsyslog
systemctl status rsyslog
The status must be running.
logger -p local2.info Test message
Publication of application events to the SIEM system is configured.
Page top