AUDISP-REMOTE(8) | System Administration Utilities | AUDISP-REMOTE(8) |
audisp-remote - plugin for remote logging
audisp-remote
audisp-remote is a plugin for the audit event dispatcher that preforms remote logging to an aggregate logging server.
If you are aggregating multiple machines, you should edit auditd.conf to set the name_format to something meaningful and the log_format to enriched. This way you can tell where the event came from and have the user name and groups resolved locally before it is sent off of the machine.
/etc/audit/audisp-remote.conf /etc/audit/plugins.d/au-remote.conf /etc/audit/auditd.conf
auditd.conf(8), auditd-plugins(5), audisp-remote.conf(5).
Steve Grubb
August 2018 | Red Hat |