本文にスキップ

rsyslog Integration

Overview

rsyslog is the default syslog daemon on most Linux distributions. KYRA MDR can receive logs from rsyslog for centralized security monitoring across Linux hosts. Supports rsyslog 8.x and later.

Prerequisites

  • A KYRA MDR Collector installed and running
  • rsyslog installed (default on RHEL, CentOS, Ubuntu, Debian)
  • Network connectivity from rsyslog hosts to the collector
  • rsyslog version 8.x or later

Configuration

Configure rsyslog to forward logs:

/etc/rsyslog.d/kyra-mdr.conf
# Forward all logs via TCP
*.* @@<collector-ip>:514
# With queue for reliability
*.* action(
type="omfwd"
target="<collector-ip>"
port="514"
protocol="tcp"
queue.type="LinkedList"
queue.filename="kyra_fwd"
queue.maxdiskspace="1g"
queue.saveonshutdown="on"
action.resumeRetryCount="-1"
)

Restart rsyslog:

Terminal window
sudo systemctl restart rsyslog

Collected Log Types

Log TypeDescriptionSecurity Use
Auth LogsAuthentication and PAM eventsLogin monitoring
Kernel LogsKernel messages and security eventsHost integrity
Cron LogsScheduled task executionCron abuse detection
Mail LogsEmail system eventsEmail security
Daemon LogsService and daemon eventsService monitoring
ApplicationCustom application syslog outputApplication security

Troubleshooting

No logs forwarded: Verify configuration with rsyslogd -N1. Use @@ for TCP.

Log loss: Configure disk-based queuing to buffer logs during collector downtime.

Rate limiting: Disable with $SystemLogRateLimitInterval 0 if you need all events.

Contact kyra@seekerslab.com for support.