Deployment Architecture

How to monitor firewall in Linux?

test_qweqwe
Builder

Hallo~!.
Someone monitoring Linux firewall?
How did you realize it?

Because windows firewall is easy to monitor.

0 Karma
1 Solution

HiroshiSatoh
Champion

By default the reject log is not recorded.
To set it entirely (regardless of the zone), enable it with the --set-log-denied option.

firewall-cmd - set-log-denied all

It is recorded in facility.level = kern.warning of syslog.
Please check "/var/log/messages".

View solution in original post

HiroshiSatoh
Champion

By default the reject log is not recorded.
To set it entirely (regardless of the zone), enable it with the --set-log-denied option.

firewall-cmd - set-log-denied all

It is recorded in facility.level = kern.warning of syslog.
Please check "/var/log/messages".

Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

[Coming Soon] Splunk Observability Cloud - Enhanced navigation with a modern look and ...

We are excited to introduce our enhanced UI that brings together AppDynamics and Splunk Observability. This is ...

Splunk Smartness with Patrick Tatro | Episode 4

Welcome to another episode of "Splunk Smartness," where we explore how Splunk Education can revolutionize your ...