خرید بک لینک

Hi,

I have set up an E.L.K Stack for capturing and visualizing Syslogs and NETFlow, but there is one slight problem.

As you know most syslogs and flows are sent by default through UDP port 514, which is a privileged port. The problem is that Logstash can not listen to any privileged ports(<1024) unless ran as root which we want to avoid doing.

I thought of setting up a Rsyslog server that listens to UDP port 514 and redirects anything that is sent to it to a higher port on lets say port 5140 to Logstash which it can listen to as it is not a privileged port.

Would anyone be able to assist me in this? Would appreciate it. I can post my current configuration if necessary.

برچسب: نویسنده: استخدام کار تاريخ: سه شنبه 21 ارديبهشت 1395 ساعت: 14:50

صفحه بندی