I need to audit an access zone on Isilon. Audit data has to be stored for +5 years, and we don't expect to look into the audit data very often (maybe once every year) so there is not high requirements for the interface.
One solution could be using syslog and Graylog:
How is the security compared to CEE and a 3' part solution (lost messages)?
The same protocol audit events are captured by Syslog Forwarding, as would be captured with CEE.
The syslog forwarding has a similar mechanism as the events forwarded by CEE, to move the pointer back to a previous point in time and resend the auditing events
The command to reset the pointer to a previous point in timed is outlined on page 17 of the following white paper
I am considering to either use syslog + Graylog or CEE and one of the suggested products (DatAdvantage/StealthAudit/Data Insight/Change Auditor). We only need the audit part, so we don't need all the extra features.
We are having several file shares that we need to audit, because of sensitive data. The file shares are in a separate Access Zone.
One more challenge is that the audit data also can be sensitive The admin of file share A is not allowed to have access to audit data from file share B. All audit data is in one stream, and can't be split to several logservers, I assume.
We are already using Graylog, so it would be easy to choose this solution.
It is fine that we can reset the pointer, but I hope that resetting the pointer not will be necessary - what happens if the Graylog/StealthAudit is unavailable for a periode?
To my understandig the CEE and syslog data can always be found Isilon (if auditing and syslog is configured), unless we choose to delete the data, correct? And if we are using syslog, we can delete the CEE data?
It seems that Isilon keeps 10 syslog files and then roll over, so we will loose audit data if Graylog is offline for more than 40 minuttes - Isilon saves a syslog file every 4 minuttes. Can you configure Isilon so that it has more than 10 syslog files?
And last: Any advice on what you can configure in the syslog.conf?
It seems that Isilon keeps 10 syslog files and then roll over, so we will loose audit data if Graylog is offline for more than 40 minuttes - Isilon saves a syslog file every 4 minuttes. Can you configure Isilon so that it has more than 10 syslog files?
The above is actually controlled by the /etc/newsyslog.conf file. The threshold for rolling the audit syslog file isn't based on time, but based on size. The /var partition on each node is relatively small, so you wouldn't want to keep to many logs here to avoid a scenario where /var fills up.
Here is the entry in /etc/newsyslog.conf
# logfilename [owner:group] mode count size when flags [/pid_file] [sig_num]
/var/log/audit_protocol.log 664 10 10000 * ZC
So the default permission on the file is 664 (rw-rw-r--)
We keep 10 of the logs
The size is 10000, but I have to look up to see what the unit used here is, as the size should be about 1Gb
The ZC indicates that we would Gzip Compress on log rotation.
As it relates to the Syslog Rolling, you also have the option to reset the pointer in the Audit Logs to an earlier point in time to reforward those logs to syslog. The following command available in OneFS 7.2 will move the Syslog Audit specific pointer in the audit logs stored under /ifs/.ifsvar/audit/logs
Example: The following will update the pointer to forward events newer than Nov 19, 2014 at 2pm
The timestamp in the syslog messages look rather random/wrong. Some of the operation I made on the Isilon is first reported hours later, and with the timestamp hours later.
scott_owens
60 Posts
3715
2
Posted July 23rd, 2015 11:00
Henrik,
The same protocol audit events are captured by Syslog Forwarding, as would be captured with CEE.
The syslog forwarding has a similar mechanism as the events forwarded by CEE, to move the pointer back to a previous point in time and resend the auditing events
The command to reset the pointer to a previous point in timed is outlined on page 17 of the following white paper
http://www.emc.com/collateral/white-papers/h12428-wp-best-practice-guide-isilon-file-system-auditing.pdf
In addition, on page 12 of the above white paper, I outline how to setup syslog forwarding.
Can you provide more information on what you are looking for as it relates to security?
Thanks,
-Scott