![]() |
![]()
| ![]() |
![]()
NAME
DESCRIPTIONNote: the configuration file may contain passwords. Care should be
taken to configure proper permissions for this file ( Every line starting with CONFIGURATION FILE SYNTAXThe general syntax of the ## Global section. # Our name. # The default is the first part of the hostname. name "<name>" # Connection timeout. # The default is 5. timeout <seconds> # Path to pidfile. # The default is "/var/run/auditdistd.pid". pidfile "<path>" sender { ## Sender section. # Source address for connections. # Optional. source "<addr>" # Directory with audit trail files managed by auditdistd. # The default is /var/audit/dist. directory "<dir>" # Configuration for the target system we want to send audit trail # files to. host "<name>" { # Source address for connections. # Optional. source "<addr>" # Address of the auditdistd receiver. # No default. Obligatory. remote "<addr>" # Directory with audit trail files managed by auditdistd. # The default is /var/audit/dist. directory "<dir>" # Fingerprint of the receiver's public key when using TLS # for connections. # Example fingerprint: # SHA256=8F:0A:FC:8A:3D:09:80:AF:D9:AA:38:CC:8A:86:53:E6:8F:B6:1C:55:30:14:D7:F9:AA:8B:3E:73:CD:F5:76:2B fingerprint "<algorithm=hash>" # Password used to authenticate in front of the receiver. password "<password>" } # Currently local audit trail files can be sent only to one remote # auditdistd receiver, but this can change in the future. } receiver { ## Receiver section. # Address to listen on. Multiple listen addresses may be specified. # The defaults are "tcp4://0.0.0.0:7878" and "tcp6://[::]:7878". listen "<addr>" # Base directory. # If the directory in the host section is not absolute, it will be # concatenated with this base directory. # The default is "/var/audit/remote". directory "<basedir>" # Path to the receiver's certificate file. # The default is "/etc/security/auditdistd.cert.pem". certfile "<path>" # Path to the receiver's private key file. # The default is "/etc/security/auditdistd.key.pem". keyfile "<path>" # Configuration for a source system we want to receive audit trail # files from. host "<name>" { # Sender address. # No default. Obligatory. remote "<addr>" # Directory where to store audit trail files received # from system <name>. # The default is "<basedir>/<name>". directory "<dir>" # Password used by the sender to authenticate. password "<password>" } # Multiple hosts to receive from can be configured. } Most of the various available configuration parameters are
optional. If a parameter is not defined in the particular section, it will
be inherited from the parent section if possible. For example, if the
CONFIGURATION OPTION DESCRIPTIONThe following statements are available:
FILES
EXAMPLESThe example configuration files can look as follows. Web server: sender { host backup { remote 10.0.0.4 } } Audit backup server: receiver { host webserv { remote 10.0.0.1 } host mailserv { remote 10.0.0.2 } host dnsserv { remote 10.0.0.3 } } SEE ALSOAUTHORSThe
|