000011922 - How to include the hostname in the syslog output for RSA Authentication Manager 8.x

Document created by RSA Customer Support Employee on Jun 14, 2016Last modified by RSA Customer Support on Apr 11, 2019
Version 3Show Document
  • View in full screen mode

Article Content

Article Number000011922
Applies ToRSA Product Set: SecurID
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
IssueAll RSA Authentication Manager log entries are written with the hostname of "localhost" in syslog..  This article explains how to include the hostname in the syslog output.

 
CauseThe local syslog server is configured by default to listen on 127.0.0.1 and will not accept connections using any configuration in the Security Console other than log to "local operating system SysLog"
 
ResolutionTo work around this issue and have the hostname present in the syslog, perform the following:

  1. Make a backup of the file /etc/syslog-ng/syslog-ng.conf.


cp /etc/syslog-ng/syslog-ng.conf./etc/syslog-ng/syslog-ng.conf.bk


  1. Open the syslog-ng.conf.in a text editor, such as vi.
  2. Edit /etc/syslog-ng/syslog-ng.conf, changing 


udp(ip("127.0.0.1") port(514));


to



udp(ip("x.x.x.x") port(514));


where, x.x.x.x is the IP address of the Authentication Manager server.  With the IP address the command is udp(ip("192.168.2.50") port(514));


  1. Restart the syslog daemon:


/etc/init.d/syslog restart


  1. Configure Authentication Manager to forward syslog events. 

    1. In the Security Console, navigate to Setup > System Settings > Logging.
    2. Select the primary server and click Next.
    3. Change the logging settings to Save to internal database and remote SysLog at the following hostname or IP address.
    4. Put the Authentication Manager's IP using in step 3 above into the field for the server to log to.
    5. Now all events logged to syslog will have the server's short hostname. By default with syslog the hostname is to the right of the date and timestamp.

Example RSA log entry:




Oct  4 09:32:18 am8p 2013-10-04 09:32:18,534, , audit.runtime.com.rsa.ims.session.impl.SessionManagerImpl,
INFO, b51d194d3202a8c01a734ebc86e27d5c,f375d7e63202a8c00822bc73cb5c8122,,192.168.2.50,
AUTHN_LOGOUT_EVENT,13001,SUCCESS,,cd4fa0343202a8c01b4a7edfce034bf7-vYx1cUR3CIFY,000000000000000000001000d0021000,
000000000000000000001000d0011000,000000000000000000001000e0011000,admin,Admin,Admin,,,,,,,,,,,,,,,,,,,,


Example non-RSA entry:




Oct  4 09:20:25 am8p sshd[5389]: Server listening on 0.0.0.0 port 22.
Legacy Article IDa62694

Attachments

    Outcomes