Best Regards, Rituraj B | |
HiI tried my best to configure the audisp-remote.I am getting below error on the client machine in /var/log/syslog.Oct 2 14:41:15 xxxxxx audisp-remote: Error connecting to 192.168.103.7: Connection refused192.168.103.7 is the IP address of the central log server.Notes: My settings are below:on server as well on client:/etc/audisp/audisp-remoteremote_server = 192.168.103.7port = 6999local_port = 6999transport = tcpqueue_file = /var/spool/audit/remote.logmode = immediatequeue_depth = 2048format = asciinetwork_retry_time = 100I have enabled name_format=HOSTNAME only in one place (in /etc/audisp/audispd.conf - and not in /etc/audit/auditd.confentries in auditd.conf:rtcp_listen_port = 6999tcp_listen_queue = 5tcp_max_per_addr = 10tcp_client_ports = 0-65535tcp_client_max_idle = 0I see the server is listening on the port 6999 as below but its not accepting client request.root@logs:/etc# lsof -i :6999COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAMEaudisp-re 9091 root 3u IPv4 33671 0t0 TCP 192.168.103.7:6999->192.168.103.7:6999 (ESTABLISHED)
Best Regards,
Rituraj B