secureworks / dcept

A tool for deploying and detecting use of Active Directory honeytokens
https://www.secureworks.com/blog/dcept
GNU General Public License v3.0
498 stars 102 forks source link

syslog configuration #3

Closed zmarkovic66 closed 8 years ago

zmarkovic66 commented 8 years ago

Hi,

I am trying to configure log event forwarding via syslog to remote server. I followed your instructions and changed dcept.cfg file by:

Unfortunately I don't see any syslog message passed to remote server. I confirmed that by running tcpdump on both servers. Is there are anything else that I missed to configure?

The dcept server is running CentOS 7 and rsyslog

thanks,

jamesscwx commented 8 years ago

Currently, DCEPT only sends syslog messages for two reasons:

You won't see a syslog message unless there's an error or a security event. You can trigger an event by replaying the example.pcap against the DCEPT interface.

tcpreplay -i example.pcap

The next update will have a startup syslog message or a heartbeat.