rsyslog Integration
Overview
rsyslog is the default syslog daemon on most Linux distributions. KYRA MDR can receive logs from rsyslog for centralized security monitoring across Linux hosts. Supports rsyslog 8.x and later.
Prerequisites
- A KYRA MDR Collector installed and running
- rsyslog installed (default on RHEL, CentOS, Ubuntu, Debian)
- Network connectivity from rsyslog hosts to the collector
- rsyslog version 8.x or later
Configuration
Configure rsyslog to forward logs:
# Forward all logs via TCP*.* @@<collector-ip>:514
# With queue for reliability*.* action( type="omfwd" target="<collector-ip>" port="514" protocol="tcp" queue.type="LinkedList" queue.filename="kyra_fwd" queue.maxdiskspace="1g" queue.saveonshutdown="on" action.resumeRetryCount="-1")Restart rsyslog:
sudo systemctl restart rsyslogCollected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Auth Logs | Authentication and PAM events | Login monitoring |
| Kernel Logs | Kernel messages and security events | Host integrity |
| Cron Logs | Scheduled task execution | Cron abuse detection |
| Mail Logs | Email system events | Email security |
| Daemon Logs | Service and daemon events | Service monitoring |
| Application | Custom application syslog output | Application security |
Troubleshooting
No logs forwarded: Verify configuration with rsyslogd -N1. Use @@ for TCP.
Log loss: Configure disk-based queuing to buffer logs during collector downtime.
Rate limiting: Disable with $SystemLogRateLimitInterval 0 if you need all events.
Contact kyra@seekerslab.com for support.