How-To Guides
...
SIEM and Syslog Integration
SIEM Server and Log Parameters Set up
3 min
kron pam can send the logs selected in the siem kron pam can send the logs selected in the siem configuration page to the syslog listener the information related to the server and content of the packets is managed with parameters defined in the system config man screen the server to which the packets are sent can be configured using the parameters listed in the table below to configure siem integration navigate to administration > system config management > integrations select siem configuration click to add siem server set the following parameters and save parameter name parameter default values possible values siem host name syslog server hostname 10 20 10 10 siem port syslog server port 514 rfc format syslog message rfcformat rfc 5424 rfc 5424, rfc 3164 protocol syslog connection protocol udp tcp, udp content format syslog message content format key value key value, cef, legacy cef establish an ssh connection to the kron pam server and restart netright tomcat with the following command \[root\@sc ]# systemctl restart netright tomcat