Send audit log entries to vRealize Log Insight via audisp-remote
I have been trying to get a RHEL 7 machine to transfer its audit log entries to a vRealize Log Insight appliance. I was able to get it going by forwarding the audit entries to rsyslog and then using the rsyslog forwarding via port 514. But, I have not been able to get audisp-remote to do the same thing. Seems the Log Insight service is not listening on port 60, and the audisp-remote service cannot connect to the vRealize box over 514. Seems I am stuck. Any advice accepted.
Responses