Set up
-
Follow the shared Log Forwarders guide to add OpenVPN Access Server and open Forwarder Details (or ask Chat for the listener
ip:port) - Connect to the Access Server console and get root privileges
-
Open
/usr/local/openvpn_as/etc/as.conf, addSYSLOG=1at the bottom of the file, and save it -
Restart Access Server with
service openvpnas restart -
Create
/etc/rsyslog.d/openvpnas.confwith a rule that forwards Access Server lines to the IP and port from Forwarder Details:- TCP:
if $programname == 'openvpnas' then @@<ip>:<port> - UDP:
if $programname == 'openvpnas' then @<ip>:<port>
@@rule sends plaintext TCP. Use it only when that TCP listener shows TLS: Disabled. If it shows TLS: Enabled,@@cannot complete the handshake, so a TCP-only forwarder receives no events. Disable TLS on the forwarder to use this rule. - TCP:
-
Restart rsyslog with
systemctl restart rsyslog - Events will begin showing up shortly
--log-driver=syslog --log-opt syslog-address=tcp://<ip>:<port> (or udp://) instead of the rsyslog rule. tcp:// is plaintext, so use it only when the TCP listener shows TLS: Disabled. See OpenVPN’s How To Log To Syslog tutorial for details.
Wirespeed parses AUTH SUCCESS results (user, status, and reason), failed VPN authentications, and authentication errors into dedicated fields. VPN daemon ([OVPN n] OUT:) lines keep their text with the client address and common name, and web service and other lines are stored with their message.
