Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

PowerScale OneFS 9.8.0.0 Web Administration Guide

Syslog forwarding and TLS

You can configure forwarding of audit logs to remote syslog servers. You can enable TLS for syslog forwarding.

For the protocol activity audit topic, you can also configure forwarding to a Dell Common Event Enabler (CEE) server. For information about forwarding audit logs to a CEE server, see Integrating with the Common Event Enabler.

To configure forwarding to remote syslog servers, you must use the CLI. Configuration includes:

  • Enabling and disabling remote forwarding
  • Specifying the remote syslog servers
  • Enabling or disabling encryption (TLS) for the forwarding operations
  • Choosing between one- or two-way authentication for TLS communications

These settings are configured separately for each audit topic. For example, you can enable forwarding of configuration change auditing while not forwarding the other audit topics. You can configure separate remote servers for each of the audit topics, and you can configure TLS separately for each audit topic. To view the current configuration for all the audit settings, use isi audit settings global view.

The OneFS audit system persists all audit data to disk. The audit syslog forwarder ensures that all audit events are processed for forwarding when remote forwarding is enabled. Only TLS ensures delivery to the remote servers.

Both TLS or non-TLS methods distribute the audit event in the same way. The audit syslog forwarder sends all audit events to all configured remote syslog servers. Use the following table to determine whether to enable TLS.

Table 1. Comparison of Remote Forwarding The following table displays the comparison of remote forwarding with TLS enabled and disabled.
Attribute TLS enabled TLS disabled
Delivery method TLS UDP
Reliability Every event is guaranteed for successful delivery to at least one remote syslog server.

If configuration errors or degraded network conditions exist, audit events may be dropped for a given remote server. If all syslog servers are down, the entire forwarding process is blocked until one server recovers.

This method is unreliable. The audit syslog forwarder does not implement UDP retransmission.
Authentication One- or two-way certificate verification is performed.
  • One-way verification—This option is the default verification method when TLS is enabled. The root certificate for the CA that is embedded in OneFS is used to verify the syslog server during the TLS handshake. No additional configuration is required.
  • Two-way verification—This option requires that both server and client certificates are verified. You must import the client certificate into OneFS for this case. Use the isi audit certificates syslog commands.
No certificate verification is performed.

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\