Re: prelude-lml and syslog message over the network
Yoann Vandoorselaere <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.user |
|---|---|
| Message-ID | <1247234165.31201.37.camel@arwen> |
Hi, Le lundi 16 mars 2009 à 16:44 +0100, [email protected] a écrit : > I am setting up PreludeIDS, and I am having a bit of a trouble with prelude-lml, on CentOS. > > Basically, I have initially set syslog to accept messages over the network and log them into files. However, because > there is quite a lot of syslog traffic, I wanted to setup prelude-lml as a listener, so that I can only accept+log > (into prelude db) events that I need. > > Problem that I have is: > > 16 Mar 11:04:20 (process:8776) WARNING: no appropriate format defined for log entry: 'sshd[24034]: > pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=172.18.100.1 user=root > > Trouble is that this message doesn't have timestamp and hostname, which are fields defined in syslog format. That's an interesting log entry, where is this coming from? > I have > tried defining 'custom' format, without timestamp/hostname, but then entries show up (in prewikka) with > 'destination' of 127.0.0.1. > > What is the proper way to handle a case like this? Unfortunately, none at the moment. The problem is that Prelude-LML won't rely on the sender IP address, since the message might have been relayed from yet another machine. I agree it would be nice to have this behavior as an option through... You might want to open a feature request on https://dev.prelude-ids.com if you are interested. Regards, -- Yoann Vandoorselaere <[email protected]> _______________________________________________ Prelude-user site list [email protected] http://lists.prelude-ids.org/mailman/listinfo/prelude-user