Centralise logs, check the clocks agree, and correlate a brute-force pattern
Task
Forward lin-b's authentication logs to lin-srv, confirm both servers' clocks are synchronised, generate a burst of failed SSH logons followed by a success, and write a correlation rule that flags exactly that pattern from the central log. This is a SIEM's core job in miniature: collect, align in time, correlate, alert.
Steps
- On lin-srv, enable rsyslog's TCP input on port 514 and write remote messages to
/var/log/remote/<hostname>.log. On lin-b, forwardauth,authpriv.*to lin-srv. Save both configuration snippets tolab/siem/rsyslog.txt. - Save
chronyc trackingfrom both servers tolab/siem/time.txt. - From the host, make eight SSH logons to lin-b with a wrong password for a test account, then one successful logon.
- Copy lin-b's central log from lin-srv to
lab/siem/lin-b.log. - Write
lab/siem/correlate.shthat reads the log and printsALERT <user> <source>when five or more failures for one user from one address are followed by a success for the same user and address. Save its output tolab/siem/alerts.txt.
Verify
These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.
grep -Ec '@@?[0-9.]+:514|imtcp' lab/siem/rsyslog.txt
grep -Ec 'System time.*(fast|slow)' lab/siem/time.txt
grep -c 'Failed password' lab/siem/lin-b.log
grep -c 'Accepted' lab/siem/lin-b.log
grep -c '^ALERT' lab/siem/alerts.txt
Forwarding is configured, both servers report their offset from their time source, the central log holds eight failures and at least one acceptance, and the rule raised exactly one alert. Run it against a log containing only failures, or only a normal logon, and it must raise none -- test both before trusting it.
Notes
If the two servers' clocks disagreed by a few minutes, the success could appear to come before the failures, and a time-ordered rule would miss the attack entirely. That is the practical reason NTP is a security control.
This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.