Balabit - syslog-ng.conf of the SCB (site 1)
Balabit SCB Solution · Config document · referenced from Basic settings, logging and monitoring
snmptrap lines use the community public towards 127.0.0.1 only. The # NOTE: lines are mine, added for this write-up.The syslog-ng configuration of the core firmware of the site 1 cluster: where the appliance's own messages come from, which local files they go to, and the one remote destination that the Syslog section of the Management page produces, the central syslog server 10.11.17.113 on TCP 514.
| Item | Value |
|---|---|
| Path | /etc/syslog-ng/syslog-ng.conf, core firmware |
| Cluster | dc1-s-xblb001, site 1; the file is not dated |
| Software | syslog-ng, configuration @version:3.8 |
| Includes | /etc/syslog-ng/conf.d/*.conf, among them message-queue-client.conf |
| Generated from | Basic Settings > Management > Syslog: Management and date and time (site 1) |
The file
@version:3.8 #### # # Global options # #### options { chain_hostnames(off); keep_hostname(on); keep_timestamp(yes); flush_lines(0); stats_freq(0); log_fifo_size(100000); }; #### # # Include # #### @include "/etc/syslog-ng/conf.d/*.conf" #### # # Sources # #### # NOTE: messages of the core firmware get the cluster name as host name. source s_core_journal { systemd-journal( host_override("dc1-s-xblb001.adm.example.net") ); unix-dgram( "/var/run/syslog-ng-dev-log" host_override("dc1-s-xblb001.adm.example.net") ); }; # NOTE: by its name, for the boot firmware of the slave node; TCP 1514, host name kept. source s_slave_boot { tcp( ip("0.0.0.0") port(1514) keep_hostname(yes) so_keepalive(yes) keep_timestamp(yes) ); }; source src { # For syslog-ng internal messages tcp( ip("127.0.0.1") port(10514) keep_hostname(yes) so_keepalive(yes) keep_timestamp(yes) host_override("dc1-s-xblb001.adm.example.net") ); }; source src-internal { internal(); }; #### # # Local destinations # #### # NOTE: local files, one per weekday, overwritten when older than 86410 s. destination d_messages { file( "/var/log/messages-$WEEKDAY" group("www-data") perm(0640) overwrite_if_older(86410) template("$ISODATE $HOST $MSGHDR$MSG\n") template_escape(no) ); }; destination d_scb { file( "/var/log/scb-$WEEKDAY" group("www-data") perm(0640) overwrite_if_older(86410) template("$ISODATE $HOST $MSGHDR$MSG\n") template_escape(no) ); }; destination d_zorp_http { file( "/var/log/zorp-http-$WEEKDAY" group("www-data") perm(0640) overwrite_if_older(86410) template("$ISODATE $HOST $MSGHDR$MSG\n") template_escape(no) ); }; destination d_zorp_ica { file( "/var/log/zorp-ica-$WEEKDAY" group("www-data") perm(0640) overwrite_if_older(86410) template("$ISODATE $HOST $MSGHDR$MSG\n") template_escape(no) ); }; destination d_zorp_rdp { file( "/var/log/zorp-rdp-$WEEKDAY" group("www-data") perm(0640) overwrite_if_older(86410) template("$ISODATE $HOST $MSGHDR$MSG\n") template_escape(no) ); }; destination d_zorp_ssh { file( "/var/log/zorp-ssh-$WEEKDAY" group("www-data") perm(0640) overwrite_if_older(86410) template("$ISODATE $HOST $MSGHDR$MSG\n") template_escape(no) ); }; destination d_zorp_telnet { file( "/var/log/zorp-telnet-$WEEKDAY" group("www-data") perm(0640) overwrite_if_older(86410) template("$ISODATE $HOST $MSGHDR$MSG\n") template_escape(no) ); }; destination d_zorp_vnc { file( "/var/log/zorp-vnc-$WEEKDAY" group("www-data") perm(0640) overwrite_if_older(86410) template("$ISODATE $HOST $MSGHDR$MSG\n") template_escape(no) ); }; #### # # Filters # #### # NOTE: a failed systemd unit becomes the alert xcbInitSystemUnitFailed (see the log paths below). filter f_failed_systemd_unit { program("systemd"); message("Unit entered failed state."); }; filter f_scb { program( "scb" type("string") flags("prefix") ); }; filter f_zorp_http { program( "zorp/scb_http" type("string") flags("prefix") ); }; filter f_zorp_ica { program( "zorp/scb_ica" type("string") flags("prefix") ); }; filter f_zorp_rdp { program( "zorp/scb_rdp" type("string") flags("prefix") ); }; filter f_zorp_ssh { program( "zorp/scb_ssh" type("string") flags("prefix") ); }; filter f_zorp_telnet { program( "zorp/scb_telnet" type("string") flags("prefix") ); }; filter f_zorp_vnc { program( "zorp/scb_vnc" type("string") flags("prefix") ); }; #### # # Rewriters # #### rewrite r_extract_failed_service_name { subst(": Unit entered failed state.$", "", value("MESSAGE")); }; #### # # Log statements # #### log { source(s_core_journal); filter(f_failed_systemd_unit); rewrite(r_extract_failed_service_name); destination { program("/usr/bin/xargs -i -n 1 /usr/bin/snmptrap -v 2c -c public 127.0.0.1 '' xcbInitSystemUnitFailed systemunit s '{}' firmware i 2" mark-mode(none) template("$MSG\n")); }; }; log { source(s_slave_boot); filter(f_failed_systemd_unit); rewrite(r_extract_failed_service_name); destination { program("/usr/bin/xargs -i -n 1 /usr/bin/snmptrap -v 2c -c public 127.0.0.1 '' xcbInitSystemUnitFailed systemunit s '{}' firmware i 1" mark-mode(none) template("$MSG\n")); }; }; log { source(src); source(s_slave_boot); source(s_core_journal); destination(d_messages); }; log { source(s_core_journal); filter(f_zorp_http); destination(d_zorp_http); }; log { source(s_core_journal); filter(f_zorp_ica); destination(d_zorp_ica); }; log { source(s_core_journal); filter(f_zorp_rdp); destination(d_zorp_rdp); }; log { source(s_core_journal); filter(f_zorp_ssh); destination(d_zorp_ssh); }; log { source(s_core_journal); filter(f_zorp_telnet); destination(d_zorp_telnet); }; log { source(s_core_journal); filter(f_zorp_vnc); destination(d_zorp_vnc); }; destination d_main { tcp("127.0.0.1" port(10514) ); }; log { source(src); source(s_slave_boot); source(s_core_journal); filter(f_scb); destination(d_scb); }; log { source(src-internal); destination(d_main); }; #### # # Remote destinations # #### # NOTE: the one remote destination, the central syslog server, TCP 514, no TLS. destination remote { syslog( "10.11.17.113" transport("tcp") port(514) template("$MSG\n") template_escape(no) ); }; #### # # Remote log statements # #### log { source(src); source(s_slave_boot); source(s_core_journal); destination(remote); };
| Block | What it does |
|---|---|
options | Host names of the senders are kept (keep_hostname(on), chain_hostnames(off)) and so are their time stamps |
s_core_journal | The systemd journal and a /dev/log-like socket of the core firmware; every message gets the host name dc1-s-xblb001.adm.example.net, so the central server sees the cluster, not the node |
s_slave_boot | A TCP listener on port 1514 on all addresses, with the sender's host name kept; as I read it, this is where the boot firmware messages arrive, the ones that carry the node ID |
src, src-internal, d_main | syslog-ng's own messages are sent to 127.0.0.1:10514 and read back there with the cluster name |
d_messages, d_scb, d_zorp_* | Local files /var/log/messages-$WEEKDAY, /var/log/scb-$WEEKDAY and one per proxy (zorp-http, -ica, -rdp, -ssh, -telnet, -vnc), readable by the group www-data. One file per weekday with overwrite_if_older(86410), one day and ten seconds, so the box keeps a week of local logs |
f_failed_systemd_unit, r_extract_failed_service_name | A message "Unit entered failed state." from systemd is cut down to the unit name and handed to snmptrap, which raises xcbInitSystemUnitFailed on the local trap receiver, with firmware i 2 for the core firmware and i 1 for the boot firmware. That is the "A system service failed" alert of Alerting and monitoring (site 1), sent as e-mail |
remote | syslog() to 10.11.17.113, transport("tcp"), port 514, template("$MSG\n") |
last log | Everything from the three sources, unfiltered, goes to the remote destination |
Two things do not match the web page. The page says the protocol is legacy-TCP, BSD syslog of RFC 3164, while the file uses syslog-ng's syslog() driver, which in the syslog-ng documentation I know is the driver for the IETF syslog protocol of RFC 5424; with the template $MSG it is not clear from the file alone what exactly went over the wire, and my material has nothing from the receiving side. And the remote destination has no filter: the security events of the connections and the operating messages of the box all go to the central server in one stream, although my syslog TODO list wanted operational logs and security logs told apart and "the right syslog prefixes" set. The forwarding from the central syslog server to the SIEM, which the analysis asked for, is not in my material.
Checked against One Identity Safeguard for Privileged Sessions 9.0
| As built | Today |
|---|---|
legacy-TCP on the web page, syslog() driver in the file | The documentation still defines legacy- as RFC 3164 and syslog- as RFC 5424; how the generated file looks today is not documented |
No TLS to 10.11.17.113 | TCP+TLS with a server certificate check against a trust store is offered |
| One file per weekday | "The retention time for local logs of SPS is seven days" |
The vendor documents describe the web settings, not the generated syslog-ng.conf, so this file cannot be compared line by line with a current one.