A A A

Please consider registering
guest

Log In

Lost password?
Advanced Search:

— Forum Scope —



— Match —



— Forum Options —




Wildcard usage:
*  matches any number of characters    %  matches exactly one character

Minimum search word length is 4 characters - maximum search word length is 84 characters

Topic RSS
Configure rsyslog to send TCP or UDP traffic to remote server.
July 18, 2017
1:03 pm
Lo0oM
Admin
Forum Posts: 217
Member Since:
September 30, 2012
Offline

Hi 

Description:

I have MySQL server and use rsyslog on RHEL to send audit traffic to remote server.

 

Solution:

1. MySQL audit have program name mysql-server_auditing (configured in MySQL DB). 

Rsyslog configuration stored in file /etc/rsyslog.conf :

 

if $programname == 'mysql-server_auditing' then @test.mydomain.com:514               (this line will sent UDP traffic)

if $programname == 'mysql-server_auditing' then @@test.mydomain.com:1514          (this line will send TCP traffic)

if $programname == 'mysql-server_auditing' then ~                                       (this line will select traffic for the next line)
& ~                                                                                                                      (this line will remove all selected traffic)

 

With above configuration you will not log MySQL audit in to the /var/log/messages. 

 

Thank you.

 

Forum Timezone: UTC 0

Most Users Ever Online: 31

Currently Online:
2 Guest(s)

Currently Browsing this Page:
1 Guest(s)

Top Posters:

Member Stats:

Guest Posters: 0

Members: 0

Moderators: 0

Admins: 1

Forum Stats:

Groups: 3

Forums: 20

Topics: 214

Posts: 214

Newest Members: Lo0oM

Administrators: Lo0oM (217)