AUDISP-REMOTE:(8) | System Administration Utilities | AUDISP-REMOTE:(8) |
audisp-remote - plugin for remote logging
audisp-remote
audisp-remote is a plugin for the audit event dispatcher that preforms remote logging to an aggregate logging server.
If you are aggregating multiple machines, you should edit auditd.conf to set the name_format to something meaningful and the log_format to enriched. This way you can tell where the event came from and have the user name and groups resolved locally before it is sent off of the machine.
/etc/audit/audisp-remote.conf /etc/audit/plugins.d/au-remote.conf /etc/audit/auditd.conf
Steve Grubb
August 2018 | Red Hat |