AUDISP-REMOTE.CONF(5) (NAME) audisp-remote.conf - audisp-remote (DESCRIPTION) audisp-remote.conf (audit) . : remote_server (hostname) . (IP) (resolvable) . port . local_port . ( ) any ( ) . . (root) (bind ). tcp_client_ports auditd.conf . transport . TCP TLS KRB5. TCP (clear text) . TLS TLS 1.3 - (post-quantum hybrid key exchange) . ( tls_psk_file) . TLS format=managed ascii TLS . KRB5 Kerberos 5 . TCP . mode . immediate forward. immediate . forward . . queue_depth . queue_file mode forward . /var/spool/audit/remote.log . queue_depth . forward mode . . format . managed (overhead) . ascii ASCII . ascii audisp-remote auditd . managed . mode forward format managed . network_retry_time . . . max_tries_per_record . . network_failure_action . . max_time_per_record . max_tries_per_record (timeout) . . network_failure_action . heartbeat_timeout (heartbeat) . . tcp_client_max_idle . . network_failure_action . ignore syslog exec warn_once suspend single halt stop. ignore . (dequeued) . syslog syslog . . . exec /path-to-script . . . warn_once_continue syslog syslog . warn_once warn_once_continue . suspend . . single (single user mode) . . stop . . halt . . stop . disk_low_action (disk low) . ignore . disk_full_action (disk full) . warn_once . disk_error_action (disk error) . warn_once . remote_ending_action . : reconnect . . . reconnect . generic_error_action . syslog . generic_warning_action . syslog . queue_error_action . stop . overflow_action . ignore syslog suspend single halt. ignore . syslog syslog . suspend . single . halt . startup_failure_action . . . ignore syslog exec warn_once warn_once_continue. ignore . syslog syslog . exec /path-to-script . warn_once syslog syslog . warn_once_continue warn_once . . enable_krb5 . Kerberos transport . transport transport (override) . . yes Kerberos 5 . no . (managed) ASCII . krb5_principal (principal) . principal . krb5_principal somename/hostname auditd.conf . krb5_client_name remote_server . krb5_client_name principal . "auditd" . principal (FQDN) (realm) : auditd/host14.example.com@EXAMPLE.COM ( "auditd" krb_client_name ). principal realm . krb5_key_file principal . (root) 0400 . /etc/audisp/audisp-remote.key . tls_auth TLS. psk . psk . tls_crypto_profile TLS . compatible system pqc. compatible TLS 1.3 PSK PQC . system . FIPS FIPS . pqc - (post- quantum hybrid key exchange) . compatible . tls_psk_file TLS-PSK. ( ) . : openssl rand -hex 32 (root) 0400 . tls_psk_identity TLS-PSK . tls_psk_file . ( ) . . tls_cipher_suites (cipher suites) TLS 1.3 (:) . . : "TLS_AES_128_GCM_SHA256:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_256_GCM_SHA384" tls_key_exchange (:) . . PQC ClientHello TLS . tls_require_pqc tls_crypto_profile=pqc . yes tls_crypto_profile pqc . no tls_crypto_profile . tls_crypto_profile . (NOTES) TLS (tls_psk_file tls_psk_identity tls_cipher_suites tls_key_exchange tls_require_pqc tls_auth tls_crypto_profile) SIGHUP . SIGHUP TLS ( ) . PSK (key rotation) SIGHUP . TIME_WAIT . : . . audisp-remote . . (reboot) . q_depth auditd.conf . q_depth audisp-remote.conf . heartbeat_timeout tcp_client_max_idle . . (SEE ALSO) audisp-remote(8) auditd.conf(5). (AUTHOR) (Steve Grubb) Red Hat 2022-07-01 AUDISP-REMOTE.CONF(5)