[Dshield] Remote logging via syslogd

Jon R. Kibler Jon.Kibler at aset.com
Mon Sep 29 14:25:51 GMT 2003


We are remotely managing a couple of Sparc boxes. We want to do centralized logging, where syslogd on the remote systems logs to our local log server. This is essentially a brain-dead configuration, if we want to do logging over the Internet in plain text. In fact, we tested the configuration and it worked first time.

However, logging in plain text will not cut it -- too much information is leaked for this to work in a production environment. What we really want to do is to route the remote logs through a secure tunnel. We were thinking this was the perfect job for stunnel, until we remembered that stunnel doesn't support UDP.

Any thoughts on an easy way to do real-time secure remote logging between Sparc boxes?

TIA for your thoughts!

Jon R. Kibler
Chief Technical Officer
A.S.E.T., Inc.
Charleston, SC  USA
(843) 849-8214

