標籤:rsyslog 設定 記錄 oca for install from cal ever
服務端
1、安裝最新版本rsyslog
sudo apt-get install software-properties-common python-software-propertiessudo add-apt-repository ppa:adiscon/v8-stable sudo apt-get updatesudo apt-get install rsyslog
2、配置目錄存放mysql審計日誌
vim /etc/rsyslog.d/50-default.conf# add: define logfiles$template Mysql-audit,"/var/log/remote_log/%app-name%/%hostname%_%fromhost-ip%_log_%app-name%_%$YEAR%-%$MONTH%-%$DAY%.log"$template Remote,"/var/log/remote_log/%hostname%_%fromhost-ip%/log_%app-name%_%$YEAR%-%$MONTH%-%$DAY%.log"# Log all messages to the dynamically formed file.:app-name,isequal,"mysql-audit" ?Mysql-audit:fromhost-ip, !isequal, "127.0.0.1" ?Remote& stop
3、安裝MySQL以及rsyslog-mysql模組,
apt-get install rsyslog-mysql mysql-server -y #安裝過程中會自動建立表
4、配置/etc/rsyslog.d/50-default.conf,以便將mysql的審計日誌本地保留一份,mysql資料庫裡寫一份
vim /etc/rsyslog.d/50-default.conf$ModLoad ommysql #載入ommysql模組,將日誌寫入mysql$template Remote,"/var/log/remote_log/%hostname%_%fromhost-ip%/log_%app-name%_%$YEAR%-%$MONTH%-%$DAY%.log"$template Mysql-audit,"/var/log/remote_log/%app-name%/%hostname%_%fromhost-ip%_log_%app-name%_%$YEAR%-%$MONTH%-%$DAY%.log":app-name,isequal,"mysql-audit" ?Mysql-audit& :ommysql:localhost,Syslog,rsyslog,123.com #在前一行的日誌匹配動作之後,繼續將日誌插入到mysql:fromhost-ip, !isequal, "127.0.0.1" ?Remote& stop #結束前面的匹配資訊,包括mysql-audit的匹配.
用戶端
1、安裝最新版本syslog
sudo apt-get install software-properties-common python-software-propertiessudo add-apt-repository ppa:adiscon/v8-stable sudo apt-get updatesudo apt-get install rsyslog
2、rsyslog配置(注意如果升級為8.30.0之後 不需要state檔案配置)
建立設定檔 /etc/rsyslog.d/mysql-audit.conf#mysql-audit.logmodule(load="imfile" PollingInterval="10") #載入模組input(type="imfile" File="/data/mysqldata/mysql_audit.log" #定義檔案位置 Tag="mysql-audit" #打tag #StateFile="/var/spool/rsyslog/mysql-audit.state" #inotify 狀態 Severity="error" #log層級 Facility="local7") #rsyslog 層級local7.* @10.25.109.64:514 #傳送log伺服器#end
3、修改syslog的記錄,過濾掉mysql日誌,不記錄本機syslog
:app-name,isequal,"mysql-audit" stop*.*;auth,authpriv.none -/var/log/syslog
4、重啟rsyslog以及設定檔案許可權
touch /var/spool/rsyslog/mysql-audit.statechown syslog.adm /var/spool/rsyslog/mysql-audit.stateusermod -G mysql syslog/etc/init.d/rsyslog restart
Ubuntu下rsyslog集中收集mysql審計日誌