Consolidating and Securing Remote Logs
The rsyslog service builds on the original system and kernel log services, including its basic configuration file, /etc/syslog.conf. The weakness of that older service is that it sends logging information to remote or central servers in cleartext. In other words, a malicious user who wants to collect information on the current state of your systems could have a field day if he or she can identify the system configured as a central logging server—unless that service is configured with the rsyslog service. Although the rsyslog service is configured primarily in the /etc/rsyslog.conf file, the way the service is started by default is rather important.
Default rsyslog Configuration
While the strength of rsyslog ...
Get Security Strategies in Linux Platforms and Applications, 3rd Edition now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.