In Part 1, we explored the significance of /etc/rsyslog.conf. Now, let's move to the hands-on section — configuring your Linux server to forward syslogs to a SIEM platform such as OTM and verifying the setup.
Requirements Before You Start
- Admin access to the Linux server.
- Linux audit logs must be enabled.
- Access to the OTM Platform GUI.
- Tip: If you face any issues, connect with your support team for a smooth integration experience.
Step-by-Step Configuration
1. Login to Your Linux Server
Use an “admin” privileged account to log in.
2. Edit the rsyslog.conf File
Open the configuration file using vi editor:
vi /etc/rsyslog.conf
3. Add a Forwarding Rule
Locate a suitable section or scroll to the bottom and add:
#### begin forwarding rule ###
*.* @IP-Address:514
#### end of forwarding rule ###
- Replace
IP-Addresswith your SIEM or collector machine's IP. - Port
514is used for UDP. Adjust if OTM requires a different port.
Example:
*.* @[192.168.1.100]:514
4. Save and Exit
After editing:
- Press
Esc - Type
:wq! - Hit
Enter
5. Restart the Rsyslog Service
To apply the changes:
service rsyslog restart
Check if the service is running without errors:
service rsyslog status
Step-by-Step Verification
Command-line verification:
Run tcpdump on the collector machine:
sudo tcpdump -i any host [LinuxServerIP] and port [Port No] -XX
This checks if syslog messages are arriving.
Platform Verification:
Login to the OTM Platform GUI and check if the logs are being processed properly.
Conclusion
With a simple but careful configuration of /etc/rsyslog.conf, you can route crucial Linux server logs into your SIEM environment — strengthening your monitoring, security and compliance capabilities.
Remember: efficient logging is the foundation of a secure and well-monitored infrastructure.