PowerSC Trusted Logging

preview_player
Показать описание
On Power Systems and the virtual machines (LPAR) it is important to get the audit, system and error logs off the VM to protect against hackers/system crackers that break in. Following their work they would likely remove, edit the logs to hid what they were doing or even trash the disk. With the logs elsewhere you can do post-mortem analysis of what happened and how to protect yourself. Trusted Logging does this over a vSCSI interface to the VIOS in a simple and clean way and even allows for Dual VIOS and Live Partition Mobility.

Рекомендации по теме
Комментарии
Автор

Thanks!
"The prerequisites for installing Trusted Logging are VIOS 2.2.1.0 and IBM® AIX 6 with Technology Level 7 or IBM AIX 7 with Technology Level 1"

KashOleg
Автор

Hi Nigel, great video. Question, you mention (around 4:45 marker) in the video that we could configure the VIOS to a logging repository so we would only have to configure forwarding on the VIOS versus every LPAR.
We are trying to do the exact same thing. We setup two method. One was vlog to local drive on VIOS and the other was using a shared storage pool ( ideal for us as we will be using PowerVC and LPM).

We did this in our lab for testing the two options. However we were not sure how to perform forwarding of the vlog entries to a log repository from the VIOS. Is this possible using the vlogs? Or do we need to also setup log forwarding from the LPARs to VIOS and then VIOS to log repository?
Please advise.

Thank you again for all of the great videos.

onewhotypescode
Автор

Hi, Trusted logging 10 to 100s of LPARs to a a few VIOSs then on the VIOS some thing like syslog to your central repository

nigelargriffiths