Security Audit Trail & System Log Integration
Cockpit maintains an immutable audit log of administrative actions, authentication attempts, and system configuration changes. The audit trail provides compliance tracking and supports security diagnostics.
Audited Events
The security subsystem logs the following events:
- Authentication: Successful logins, logouts, password modifications, authentication failures, and account lockouts.
- Virtual Machine Lifecycle: Provisioning, deletion, power state changes, resource scaling, and live migrations.
- Resource Configuration: Creating network bridges, formatting storage datastores, and registering physical hosts.
- Access Control Changes: Creating user accounts, altering group memberships, and assigning scoped permissions.
Log Entry Schema
Each audit log entry contains structured metadata to record the context of the event:
- Timestamp: High-precision UTC timestamp (conforming to ISO 8601) indicating when the event occurred.
- Subject: The username and origin IP address of the administrator who executed the command.
- Action: The action identifier (e.g.,
VM_POWER_OFF,USER_CREATED). - Object: The unique identifier (UUID) and name of the target resource (e.g., VM
sales-reporting-app). - Status: The outcome of the action (success, failure with error details, or blocked due to insufficient permissions).
SIEM and Syslog Forwarding
For enterprise compliance and centralized security analysis, Cockpit can forward audit logs in real-time to external Security Information and Event Management (SIEM) systems (such as Splunk or Elasticsearch).
Configuring Syslog Forwarding:
- Log into the Cockpit console with administrative credentials.
- Navigate to Settings > System > Syslog Forwarding.
- Select Add Forwarding Target.
- Configure the destination properties:
- Host: The IP address or hostname of the syslog collector.
- Protocol: Select
UDP,TCP, orTLS(TLS is recommended to encrypt log payloads in transit). - Port: Typically
514for standard syslog traffic, or a custom port defined by your security team. - Format: Select
RFC 5424(structured syslog format) orJSONformat.
- Save the configuration to initialize real-time log streaming.