Centralise logs, check the clocks agree, and correlate a brute-force pattern

short · 50 min · Objective 3.4

Task

Forward lin-b's authentication logs to lin-srv, confirm both servers' clocks are synchronised, generate a burst of failed SSH logons followed by a success, and write a correlation rule that flags exactly that pattern from the central log. This is a SIEM's core job in miniature: collect, align in time, correlate, alert.

Steps

  1. On lin-srv, enable rsyslog's TCP input on port 514 and write remote messages to /var/log/remote/<hostname>.log. On lin-b, forward auth,authpriv.* to lin-srv. Save both configuration snippets to lab/siem/rsyslog.txt.
  2. Save chronyc tracking from both servers to lab/siem/time.txt.
  3. From the host, make eight SSH logons to lin-b with a wrong password for a test account, then one successful logon.
  4. Copy lin-b's central log from lin-srv to lab/siem/lin-b.log.
  5. Write lab/siem/correlate.sh that reads the log and prints ALERT <user> <source> when five or more failures for one user from one address are followed by a success for the same user and address. Save its output to lab/siem/alerts.txt.

Verify

These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.

grep -Ec '@@?[0-9.]+:514|imtcp' lab/siem/rsyslog.txt
grep -Ec 'System time.*(fast|slow)' lab/siem/time.txt
grep -c 'Failed password' lab/siem/lin-b.log
grep -c 'Accepted' lab/siem/lin-b.log
grep -c '^ALERT' lab/siem/alerts.txt

Forwarding is configured, both servers report their offset from their time source, the central log holds eight failures and at least one acceptance, and the rule raised exactly one alert. Run it against a log containing only failures, or only a normal logon, and it must raise none -- test both before trusting it.

Notes

If the two servers' clocks disagreed by a few minutes, the success could appear to come before the failures, and a time-ordered rule would miss the attack entirely. That is the practical reason NTP is a security control.

This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.