Monitoring SSH Activity with SIEM Agent

This section provides an overview of monitoring SSH (Secure Shell) activity with Powertech SIEM Agent for IBM i.

NOTE: Detailed instructions can be found in the Fortra article: Setting up and testing monitoring of SSH Activity with SIEM Agent.

Requirements

Successful monitoring of SSH Activity with SIEM Agent requires the following:

  1. SSH is already configured and working on the IBM i.

  2. You can connect via SSH from another system to the IBM i in order to test the configuration.

  3. Basic configuration of Powertech SIEM Agent for IBM i has been performed. Specifically, Outputs have been defined and events are flowing to them.

  4. The path of the SSHD configuration file is known.

TIP: The path is typically: /QOpenSys/QIBM/UserData/SC1/OpenSSH/etc/sshd_config

Data Flow

Correct configuration results in the following flow of data:

  1. An SSH client connects to an SSH server and performs actions.

  2. On the IBM i server, the SSH daemon sends events to the local Syslog daemon.

  3. The Syslog daemon sends events to a local log file.

  4. Events added to the log file cause journal entries to be created.

  5. SIEM Agent ingests the journal entries.

  6. SIEM Agent forwards the journal entries as events to the defined Outputs.