corrected rsyslog settings
This commit is contained in:
@@ -49,9 +49,6 @@
|
||||
# Forward all audit logs to a remote server via TLS
|
||||
# This file is managed by Ansible.
|
||||
|
||||
# Define the CA certificate rsyslog should trust
|
||||
global(DefaultNetstreamDriverCAFile="{{ rsyslog_tls_ca_cert }}")
|
||||
|
||||
# Define the forwarding rule
|
||||
if $programname == 'audisp-syslog' then {
|
||||
action(type="omfwd"
|
||||
|
||||
@@ -57,15 +57,15 @@
|
||||
template="gelf"
|
||||
StreamDriver="gtls"
|
||||
StreamDriverMode="1"
|
||||
StreamDriver.AuthMode="x509/name"
|
||||
StreamDriver.PermittedPeer="{{ log_forwarding_permitted_peer }}"
|
||||
StreamDriverAuthMode="x509/name"
|
||||
StreamDriverPermittedPeers="{{ log_forwarding_permitted_peers }}"
|
||||
)
|
||||
}
|
||||
notify: restart rsyslog
|
||||
when:
|
||||
- log_forwarding_type == 'gelf'
|
||||
- log_forwarding_target is defined
|
||||
- log_forwarding_permitted_peer is defined
|
||||
- log_forwarding_permitted_peers is defined
|
||||
|
||||
- name: Bastionhost | rsyslog forwarding | Configure standard TLS forwarding for SSH logs
|
||||
ansible.builtin.copy:
|
||||
@@ -86,12 +86,12 @@
|
||||
template="RSYSLOG_SyslogProtocol23Format"
|
||||
StreamDriver="gtls"
|
||||
StreamDriverMode="1"
|
||||
StreamDriver.AuthMode="x509/name"
|
||||
StreamDriver.PermittedPeer="{{ log_forwarding_permitted_peer }}"
|
||||
StreamDriverAuthMode="x509/name"
|
||||
StreamDriverPermittedPeer="{{ log_forwarding_permitted_peers }}"
|
||||
)
|
||||
}
|
||||
notify: restart rsyslog
|
||||
when:
|
||||
- log_forwarding_target is defined
|
||||
- log_forwarding_permitted_peer is defined
|
||||
- log_forwarding_permitted_peers is defined
|
||||
- log_forwarding_type == 'syslog'
|
||||
Reference in New Issue
Block a user