Skip to main content
Question

 Sending auditd Logs to Chronicle via Syslog on RHEL 8/9

  • July 29, 2025
  • 2 replies
  • 247 views

Mike
Forum|alt.badge.img

 

Hi everyone,

We're using Chronicle (Google SecOps) as our SIEM, with a log forwarder configured to receive syslog data (on UDP port 10519) — including auditd logs (on UDP port 10518).

We now want to reliably forward auditd logs to syslog on RHEL 8 and RHEL 9 systems, so they can be ingested by Chronicle through the forwarder.

What We Found
We’ve reviewed the official documentation:
https://cloud.google.com/chronicle/docs/ingestion/auditd

However:

It focuses on Debian/Ubuntu systems only

Most other tutorials we found are outdated or rely on deprecated components like audispd-plugins

Our Goal
Use the native auditd configuration on RHEL 8/9

Forward audit logs to rsyslog, which then sends them to Chronicle

Avoid deprecated or unnecessary plugins if possible

What We’re Asking
What’s the recommended way on RHEL 8/9 to forward auditd logs to rsyslog?

Should we still use audisp-syslog, or is there a more modern alternative?

Is there any validated or community-tested setup specifically for RHEL systems?

Thanks in advance for your support 
We’re aiming to implement this cleanly and will gladly share back an updated guide once it's working.

 

2 replies

kentphelps
Staff
Forum|alt.badge.img+11
  • Staff
  • August 8, 2025

Please check this Collect Linux auditd and AIX systems logs doc and let us know if it helps here.


Mike
Forum|alt.badge.img
  • Author
  • New Member
  • August 18, 2025

Hello, I found this link and modified it to work with RHEL ==>  https://cloud.google.com/chronicle/docs/ingestion/auditd?hl=fr