2017-01-19 05:40 PM
On 10.6.x Log Collectors, the SELinux environment prevents the SCP protocol from working with the default configuration. The following steps allow the SCP protocol to function.
Log Collector versions 10.6.2 and Later
The Log Collector configures SELinux to run Enforcing mode. This is required for the plugin collection protocol. If you have AWS Cloudtrail or Microsoft Azure event sources on a Log Collector, SELinux must remain in Enforcing mode.
The recommendation is to use a separate VLC for the File collection event sources using SCP. On this VLC, disable SELinux as mentioned below for Log Collector 10.6.0 and Later. This step MUST be performed whenever the Log Collector RPM is updated on this VLC.
Log Collector versions 10.6.0 and Later
By default, SELinux runs in Permissive mode. Disabling SELinux resolves the problem.
To configure RSA version 10.6.0 and 10.6.1 Log Collectors:
SELinux status: disabled
2017-02-06 05:14 AM
So customers now have to set up a separate Virutal Log Collector if they want to use Azure or AWS log collection? This is not very user friendly.