1
00:00:00,360 --> 00:00:02,040
The analysis of logs

2
00:00:02,040 --> 00:00:03,750
are one of the biggest important things you're going to do

3
00:00:03,750 --> 00:00:05,700
as a system administrator.

4
00:00:05,700 --> 00:00:09,630
Everything that happens in the system is logged typically.

5
00:00:09,630 --> 00:00:12,270
And so being able to process the information

6
00:00:12,270 --> 00:00:15,420
and also not deal with information overload

7
00:00:15,420 --> 00:00:18,180
by only keying in on specific information that's relevant

8
00:00:18,180 --> 00:00:21,930
to what you're trying to do, will also be key.

9
00:00:21,930 --> 00:00:25,133
So we're going to go through and configure the rsyslog

10
00:00:25,133 --> 00:00:27,840
and we're going to set it up to send information remotely

11
00:00:27,840 --> 00:00:29,517
to our partners server.

12
00:00:29,517 --> 00:00:32,670
And we're also going to check out the journal control command

13
00:00:32,670 --> 00:00:34,380
and our last command.

14
00:00:34,380 --> 00:00:35,760
And again, this is going to give us a lot information

15
00:00:35,760 --> 00:00:38,250
of different type of logs that are on the system.

16
00:00:38,250 --> 00:00:39,450
So first thing we need to do,

17
00:00:39,450 --> 00:00:41,190
we're going to modify our rsyslog,

18
00:00:41,190 --> 00:00:44,700
log and config file in order to send the information

19
00:00:44,700 --> 00:00:46,530
to our partner server.

20
00:00:46,530 --> 00:00:48,030
So let's do that really quick.

21
00:00:51,480 --> 00:00:53,910
Okay, so we're in this log.

22
00:00:53,910 --> 00:00:57,600
Now what we need to do is change the configuration settings

23
00:00:57,600 --> 00:01:00,270
to allow us to provide the TCP connection.

24
00:01:00,270 --> 00:01:02,663
Okay, so that's where we're going to go down here first,

25
00:01:07,530 --> 00:01:08,730
go into modules.

26
00:01:08,730 --> 00:01:10,560
We're just going to go here to where it says

27
00:01:10,560 --> 00:01:12,723
provide TCP syslog reception.

28
00:01:13,620 --> 00:01:15,450
Okay, so now the hashtag

29
00:01:15,450 --> 00:01:17,130
means that it's going to be commented out

30
00:01:17,130 --> 00:01:18,960
and that line won't be processed

31
00:01:18,960 --> 00:01:19,950
but we need to process line.

32
00:01:19,950 --> 00:01:22,920
So pretty much we want to make sure this line here,

33
00:01:22,920 --> 00:01:27,920
ModLoad imtcp and also input TCP server run 601.

34
00:01:29,837 --> 00:01:31,950
That's the port we're going to be using

35
00:01:31,950 --> 00:01:33,903
to transmit our log information.

36
00:01:34,740 --> 00:01:35,610
Okay, now we're going to go down.

37
00:01:35,610 --> 00:01:36,910
We're going to see the rules.

38
00:01:38,220 --> 00:01:42,030
And again, these rules pretty much identify a faculty

39
00:01:42,030 --> 00:01:43,740
and the severity of the log

40
00:01:43,740 --> 00:01:45,940
that we want to do something with

41
00:01:47,190 --> 00:01:48,630
and all the way to the right.

42
00:01:48,630 --> 00:01:50,550
It's going to be the action we're going to take.

43
00:01:50,550 --> 00:01:53,430
And when we just have the file locations

44
00:01:53,430 --> 00:01:54,690
that's letting the system know,

45
00:01:54,690 --> 00:01:57,480
Hey, whenever you get one of these faculties

46
00:01:57,480 --> 00:01:59,640
with whatever severity you wanted to use,

47
00:01:59,640 --> 00:02:01,770
we're going to send that to var log messages.

48
00:02:01,770 --> 00:02:02,670
What we're going to focus on

49
00:02:02,670 --> 00:02:04,710
is the failed attempts at logging in.

50
00:02:04,710 --> 00:02:06,150
So we're going to set this up

51
00:02:06,150 --> 00:02:11,150
to send all of our authorization logs to a remote server

52
00:02:11,580 --> 00:02:15,063
and then we'll better review it from there, okay.

53
00:02:15,063 --> 00:02:16,413
So, I'm going to go down here.

54
00:02:18,480 --> 00:02:20,817
We're going to add this line, authpriv.

55
00:02:24,150 --> 00:02:28,350
that means any level of severity from this type of faculty.

56
00:02:28,350 --> 00:02:30,720
Okay, we're going to do @@ now what that means

57
00:02:30,720 --> 00:02:34,170
is we're going to use TCP as our protocol, okay?

58
00:02:34,170 --> 00:02:38,250
So we're do 10.0.2.16

59
00:02:38,250 --> 00:02:39,843
that's the partner server.

60
00:02:40,770 --> 00:02:43,680
We're going to use port 601, so that's a socket, okay.

61
00:02:43,680 --> 00:02:45,330
So we have the IP address.

62
00:02:45,330 --> 00:02:47,820
The port which is a socket, two at symbols

63
00:02:47,820 --> 00:02:49,740
meaning we're going to use a TCP protocol.

64
00:02:49,740 --> 00:02:52,770
Okay, and last thing we wanted to do is we want to edit this.

65
00:02:52,770 --> 00:02:53,603
Like I was saying earlier

66
00:02:53,603 --> 00:02:55,980
we don't want all information at all times.

67
00:02:55,980 --> 00:02:58,980
Sometimes we want to specify to a certain level of severity.

68
00:02:58,980 --> 00:03:03,420
So we're going to change the info text with a notice text.

69
00:03:03,420 --> 00:03:05,100
It's going to be a level five severity.

70
00:03:05,100 --> 00:03:07,320
So anything level five severity and above

71
00:03:07,320 --> 00:03:10,170
meaning four, three, two, one, that will be sent.

72
00:03:10,170 --> 00:03:12,810
So anything info below, it's not going to be sent here.

73
00:03:12,810 --> 00:03:14,510
So let's go ahead and change this.

74
00:03:16,014 --> 00:03:18,477
This info, notice, save this.

75
00:03:22,650 --> 00:03:23,550
Let's go and exit.

76
00:03:25,170 --> 00:03:27,330
So we're going to restart our rsyslog, okay.

77
00:03:27,330 --> 00:03:30,723
So we're going to do sudo system control.

78
00:03:38,880 --> 00:03:40,650
Okay, again, this is to let the system know,

79
00:03:40,650 --> 00:03:43,860
Hey, we need you to reread that configuration file

80
00:03:43,860 --> 00:03:45,840
cause we made some changes to it.

81
00:03:45,840 --> 00:03:47,130
Okay, last but not least

82
00:03:47,130 --> 00:03:51,090
we must modify the firewall rules to allow that port 601

83
00:03:51,090 --> 00:03:53,340
that we just enable to be able to go in

84
00:03:53,340 --> 00:03:55,623
and out of our network, okay.

85
00:03:58,860 --> 00:04:02,823
Firewall command for our zone.

86
00:04:07,710 --> 00:04:09,250
Add port 601 TCP.

87
00:04:14,430 --> 00:04:15,730
We'll make this permanent.

88
00:04:18,089 --> 00:04:20,853
Okay, lets do a system control.

89
00:04:23,430 --> 00:04:24,730
I'll restart the firewall.

90
00:04:29,910 --> 00:04:33,123
Okay, make sure that rule was added successfully.

91
00:04:45,300 --> 00:04:47,373
Okay, we see 601 should be allowed.

92
00:04:50,100 --> 00:04:51,300
Now let's test this out.

93
00:04:53,040 --> 00:04:54,630
We're going to create an error.

94
00:04:54,630 --> 00:04:57,960
I'm going to log into, just count ariley,

95
00:04:57,960 --> 00:04:59,810
and purposely put the wrong password.

96
00:05:02,610 --> 00:05:04,470
Now it may take a little bit for the configurations

97
00:05:04,470 --> 00:05:08,460
to fully go through, but we're going to add ssh to the server.

98
00:05:16,350 --> 00:05:18,240
Okay, now we're going to switch to root,

99
00:05:18,240 --> 00:05:20,903
so we're able to have access to that particular folder.

100
00:05:23,400 --> 00:05:28,400
All right, so now we should be able to see the last command.

101
00:05:30,600 --> 00:05:33,960
I'm sorry, the last set of violations.

102
00:05:33,960 --> 00:05:36,633
We're going to search it by ariley.

103
00:05:37,770 --> 00:05:40,740
All right, now we see we're on the root server two

104
00:05:40,740 --> 00:05:42,597
cause we added ssh into server.

105
00:05:42,597 --> 00:05:47,100
And we can see now that there is a password failure

106
00:05:47,100 --> 00:05:49,590
for the ariley and it's highlighted.

107
00:05:49,590 --> 00:05:50,910
And again, that comes from us,

108
00:05:50,910 --> 00:05:52,800
moves in server01.

109
00:05:52,800 --> 00:05:54,570
Cause it sent the information over

110
00:05:54,570 --> 00:05:57,330
and also you can identify that in about the fourth row.

111
00:05:57,330 --> 00:05:58,620
We'll see server01,

112
00:05:58,620 --> 00:06:00,600
that's the source of that information.

113
00:06:00,600 --> 00:06:03,810
So that was a successful remote configuration

114
00:06:03,810 --> 00:06:04,643
for the rsyslog.

115
00:06:06,180 --> 00:06:07,290
Now, since we're in this root server,

116
00:06:07,290 --> 00:06:09,210
we're going to have continue to use this one.

117
00:06:09,210 --> 00:06:10,140
And we're just going to go through

118
00:06:10,140 --> 00:06:13,590
and try out the journal control commands.

119
00:06:13,590 --> 00:06:16,620
Now again, the journal control is the command

120
00:06:16,620 --> 00:06:18,450
for the journal Damon.

121
00:06:18,450 --> 00:06:21,060
Again, that runs as soon the system starts up

122
00:06:21,060 --> 00:06:23,910
and it collects a plethora of logs

123
00:06:23,910 --> 00:06:25,500
and this groups everything in together

124
00:06:25,500 --> 00:06:28,200
and you're able to use the journal control command

125
00:06:28,200 --> 00:06:31,260
to specify what type of information you want to filter down

126
00:06:31,260 --> 00:06:33,420
to exactly what you need.

127
00:06:33,420 --> 00:06:34,870
So let's use journal control.

128
00:06:36,720 --> 00:06:39,300
Okay, now we see there's a lot of information.

129
00:06:39,300 --> 00:06:41,940
We're talking about kernel initialization.

130
00:06:41,940 --> 00:06:46,260
We're talking about any type of hard dis memory,

131
00:06:46,260 --> 00:06:47,093
you name it.

132
00:06:47,093 --> 00:06:48,003
Everything's stored.

133
00:06:51,270 --> 00:06:53,250
Okay, see it's a lot of information here.

134
00:06:53,250 --> 00:06:54,840
Let's get out of here.

135
00:06:54,840 --> 00:06:57,930
Now we can also, like I said, tailoring

136
00:06:57,930 --> 00:06:59,460
only on information that we need.

137
00:06:59,460 --> 00:07:01,053
So look for a notice level.

138
00:07:04,680 --> 00:07:06,900
Okay, so notice level of severities.

139
00:07:06,900 --> 00:07:08,333
That's what we're looking at now.

140
00:07:12,660 --> 00:07:16,653
Again, it's a lot of those, okay.

141
00:07:18,832 --> 00:07:20,730
Again, we can search through this as well.

142
00:07:20,730 --> 00:07:23,190
Again, we can always use grep for anything.

143
00:07:23,190 --> 00:07:25,740
We want to focus on something from the kernel.

144
00:07:25,740 --> 00:07:28,110
Okay, easy as that.

145
00:07:28,110 --> 00:07:32,730
Again, journal control tailors down the massive monologues

146
00:07:32,730 --> 00:07:35,070
to only what we're looking for.

147
00:07:35,070 --> 00:07:38,643
Okay, now also if you want to get the most recent journals,

148
00:07:41,100 --> 00:07:43,560
do that and it also gives us an update

149
00:07:43,560 --> 00:07:46,080
as things are coming in as well.

150
00:07:46,080 --> 00:07:48,930
So it's not only for as snapshot.

151
00:07:48,930 --> 00:07:53,193
It's going to add new information too, okay.

152
00:07:54,060 --> 00:07:56,850
We're also able to specify the time

153
00:07:56,850 --> 00:08:00,090
so we can use journal troll again,

154
00:08:00,090 --> 00:08:03,427
and we're going to be able to use since "2 hours ago"

155
00:08:09,180 --> 00:08:14,180
and until "30 minutes ago."

156
00:08:18,270 --> 00:08:21,540
Okay, oo we can see that if we look at the time

157
00:08:21,540 --> 00:08:22,373
that's what it's going to be through.

158
00:08:22,373 --> 00:08:23,640
Now, you can't reference the time

159
00:08:23,640 --> 00:08:26,370
that I'm currently using cause We're still remote,

160
00:08:26,370 --> 00:08:29,160
but it's going to be from the past two hours

161
00:08:29,160 --> 00:08:30,483
up to 30 minutes ago.

162
00:08:42,480 --> 00:08:43,620
And the last one, at least we want to look at

163
00:08:43,620 --> 00:08:47,370
how to specify information for a particular service.

164
00:08:47,370 --> 00:08:49,830
So again, we're going to go use journal, the u option

165
00:08:49,830 --> 00:08:52,030
that's to let us specify a specific service.

166
00:08:55,890 --> 00:09:00,270
Okay, so everything relative to HTTP, the Apache server

167
00:09:00,270 --> 00:09:01,260
we can see that,

168
00:09:01,260 --> 00:09:03,270
not a lot hasn't been going on with Apache server.

169
00:09:03,270 --> 00:09:06,630
We just started and it seems to be going good for us so far.

170
00:09:06,630 --> 00:09:09,450
Last but not least, the last command.

171
00:09:09,450 --> 00:09:11,880
Let's go give us our last set of logins.

172
00:09:11,880 --> 00:09:13,050
So, it's only what it's focused on,

173
00:09:13,050 --> 00:09:16,023
is logging in and logging in out, okay.

174
00:09:16,920 --> 00:09:17,970
We see some of this information.

175
00:09:17,970 --> 00:09:22,683
We can see myself logging in from a remote location.

176
00:09:26,460 --> 00:09:28,755
You can see still logged in right here, server01,

177
00:09:28,755 --> 00:09:30,750
that's what I logged in as

178
00:09:30,750 --> 00:09:33,210
when I first switched over to ssh,

179
00:09:33,210 --> 00:09:35,410
when I was able to look through remote logs.

180
00:09:36,600 --> 00:09:39,210
We're also going to use the last B command.

181
00:09:39,210 --> 00:09:41,160
And what that does is this shows a list

182
00:09:41,160 --> 00:09:43,680
of bad login attempts.

183
00:09:43,680 --> 00:09:45,210
Okay, so all these are the failure.

184
00:09:45,210 --> 00:09:47,460
Okay, and then last but not least again,

185
00:09:47,460 --> 00:09:48,813
use to the last log.

186
00:09:49,980 --> 00:09:52,080
I'm going to verify that we can see the last time

187
00:09:52,080 --> 00:09:53,553
that each user logged in.

188
00:09:54,900 --> 00:09:58,020
All right, we went over how to use the rsyslog

189
00:09:58,020 --> 00:10:02,460
to remotely send our logs to a remote server

190
00:10:02,460 --> 00:10:04,470
and how to also use the journal control

191
00:10:04,470 --> 00:10:06,630
and the last command to get detailed information

192
00:10:06,630 --> 00:10:07,530
from our logs.

193
00:10:07,530 --> 00:10:10,980
So we're able to troubleshoot, identify malicious behavior,

194
00:10:10,980 --> 00:10:12,453
or spot misconfigurations.

195
00:10:13,320 --> 00:10:14,550
Thank you for sticking through this walkthrough

196
00:10:14,550 --> 00:10:16,350
and I'll see you in the next lesson.

