How to send the audit log to your own syslog or SIEM
Export the audit trail off the node over verified TLS using RFC 5424 syslog, with a private CA if you need one.
The audit log records who did what, when, from where and on what, admins included. Exporting it off the node is the only protection if the node itself is compromised.
Steps
- Check whether it is sending:
panel auditoria-externa - Set the destination:
panel auditoria-externa-destino syslog+tls://logs.example.com:6514 - If your SIEM uses a private CA, upload that CA on Security, Audit. It is trusted for that destination only.
- Check entries arrive. The format is RFC 5424 with octet-counted framing, understood by rsyslog, Graylog and Splunk.
Notes
- With
syslog+tls://the server certificate is always verified; there is no switch to skip it. Plainsyslog://is accepted for trusted internal networks. - If the destination is down, entries are queued and retried, and the advisor warns while sending is stuck.
- To turn it off use
-as the destination. That action is itself sent before it stops.
Last updated: 2026-10-10