我在/etc/rsyslog.conf中有這兩個參數
$ModLoad imjournal # provides access to the systemd journal
...
# Turn off message reception via local log socket;
# local messages are retrieved through imjournal now.
$OmitLocalLogging on
我在使用 SELinux 時遇到了問題,Rsyslog 記錄了以下內容:
Jun 6 10:53:14 vpod1-logm-front-3 rsyslogd: fopen() failed: 'Permission denied', path: '/var/spool/imjournal.state.tmp' [v8.24.0 try http://www.rsyslog.com/e/2013 ]
我必須添加一個新策略(由audit2alow產生)
cat >syslog-imjournal.te << EOF
module syslog-imjournal 1.0;
require {
type syslogd_t;
type var_spool_t;
class dir { add_name remove_name write };
class file { create rename unlink write };
}
#============= syslogd_t ==============
allow syslogd_t var_spool_t:dir write;
allow syslogd_t var_spool_t:dir { add_name remove_name };
allow syslogd_t var_spool_t:file { create rename unlink write };
EOF
checkmodule -m -o syslog-imjournal.m syslog-imjournal.te
semodule_package --module syslog-imjournal.m --outfile syslog-imjournal.pp
semodule --install=syslog-imjournal.pp --priority=400
不知道這樣做是否安全,有沒有更好的方法?
答案1
我認為問題在於您將“imjournal.state”檔案儲存在錯誤的位置,因此 SELinux 阻止寫入。您不應建立授予過多權限的自訂策略模組,而應使用預設位置,即 /var/lib/rsyslog。預設配置說:
$WorkDirectory /var/lib/rsyslog
$IMJournalStateFile imjournal.state