Sending data to Auditconsole via mlogc

本文介绍如何通过mlogc配置ModSecurity,将审计事件数据发送到审计控制台进行集中监控。包括mlogc.conf及modsecurity.conf的设置步骤,以及解决过程中遇到的权限和空间不足等问题。
摘要由CSDN通过智能技术生成

In this article, How to Sending data to Auditconsole via mlogc? Step-by-step configure Auditconsole and mlog. Auditconsole recevie audit-event data from modsecurity module. Auditconsole  mlogc

Configure Mlogc and Modsecurity

Links:
Sending data to Auditconsole via mlogc
AuditConsole failed to restart after crash

Auditconsole  mlogc

Auditconsole mlogc

Configure mlogc.conf in folder /modsecurity/mlogc/mlogc.conf

CollectorRoot       “/var/log/mlogc”
ConsoleURI          https://CONSOLE_IP_ADDRESS:8080/rpc/auditLogReceiver
SensorUsername      “name-sensor”
SensorPassword      “password-sensor”
LogStorageDir       “data”

Note:

  • ConsoleURI: ip address of Auditconsole
  • SensorUsername and SensorPassword: create in Auditconsole

Configure modsecurity.conf

SecAuditEngine RelevantOnly
SecAuditLogType Concurrent
SecAuditLogParts ABIDEFGHZ
SecAuditLogStorageDir /var/log/mlogc/data

Note:

  • SecAuditLogStorageDir same with CollectorRoot/LogStorageDir inmlogc.conf
  • Running mlogc will create 2 file mlogc-error.log and mlogc-transaction.log.

Running Command to sending log to Auditconsole

# cd /path/to/modsecurity/mlogc
# ./mlogc-batch-load.pl /var/log/mlogc/data /opt/mod_security/mlogc/mlogc /opt/mod_security/mlogc/mlogc.conf

View error in file mlogc-error.log using command

# tailf /var/log/mlogc/mlogc-error.log

Error mlogc

[Sat Apr 26 05:00:23 2014] [1] [22610/0] Failed to create global mutex: No space left on device
[Sat Apr 26 05:00:23 2014] [3] [22610/0] ModSecurity Audit Log Collector 2.8.0-RC1 terminating with error 1
[Sat Apr 26 05:00:34 2014] [3] [22612/0] Configuring ModSecurity Audit Log Collector 2.8.0-RC1.
[Sat Apr 26 05:00:34 2014] [3] [22612/0] Delaying execution for 5000ms.
[Sat Apr 26 05:00:39 2014] [1] [22612/0] Failed to create global mutex: No space left on device
[Sat Apr 26 05:00:39 2014] [3] [22612/0] ModSecurity Audit Log Collector 2.8.0-RC1 terminating with error 1
[Sat Apr 26 05:10:47 2014] [3] [22634/0] Configuring ModSecurity Audit Log Collector 2.8.0-RC1.
[Sat Apr 26 05:10:47 2014] [3] [22634/0] Delaying execution for 5000ms.
[Sat Apr 26 05:10:52 2014] [1] [22634/0] Failed to create global mutex: No space left on device
[Sat Apr 26 05:10:52 2014] [3] [22634/0] ModSecurity Audit Log Collector 2.8.0-RC1 terminating with error 1

Solve problem : Auditconsole  mlogc

# echo 512 32000 100 512 > /proc/sys/kernel/sem

Error Permistion create
Assume path to data contain logs in folder /path/to/logs/data

# chmod 755 /path /path/to
# chmod 770 /path/to/logs /path/to/logs/data
#chmod g+s /path/to/logs/data

Note: Set permistion folder /path/to/logs/data to create logs modsecurity 7(rwx) 5(rx)

Conclusion: Sending data to Auditconsole via mlogc  help easy monitoring logs of modsecurity. Auditconsole  mlogc

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值