Information
Network stream drivers are a layer between various parts of rsyslogd (e.g. the imtcp module) and the transport layer. They provide sequenced delivery, authentication and confidentiality to the upper layers. Drivers implement different capabilities.
Note: While gtls (GnuTLS) is used in this recommendation, ossl (OpenSSL via rsyslog-openssl) is an acceptable alternative stream driver. Replace DefaultNetstreamDriver gtls with DefaultNetstreamDriver ossl and ensure rsyslog-openssl is installed if using the OpenSSL driver.
StreamDriver must be set to gtls to enable TLS for encrypting syslog traffic.
Solution
Edit rsyslog.conf or a .conf file in /etc/rsyslog.d/ to use gtls :
Example /etc/rsyslog.d/40-forward.conf
# certificate files - just CA for a client
global(DefaultNetstreamDriverCAFile="/path/to/contrib/gnutls/ca.pem")
# set up the action for all messages
action(type="omfwd" protocol="tcp" target="s.example.net" port="6514"
StreamDriver="gtls" StreamDriverMode="1" StreamDriverAuthMode="anon")
Impact:
If the TLS stream driver is not configured, syslog traffic is transmitted in cleartext and is susceptible to interception. Certificate management overhead is required; if the CA certificate expires or the path is misconfigured, encrypted log forwarding will fail until the trust chain is restored.