SINGLE CONNECT
...
8 Single Connect Logs
8.8 SIEM Configuration
4 min
single connect can send logs to siem systems rfc 5424 and rfc 3164 formats are supported siem host ip address, port, rfc format and content format are configurable setting siem server and log parameters log in to the single connect gui navigate to administration > system config management set the server address, log type etc save parameter default value possible values syslog server hostname syslog server port 514 syslog message rfcformat rfc 5424 rfc 5424, rfc 3164 syslog message content format key value key value, cef siem log configuration log in to the single connect gui navigate to siem configuration select log type and maximum record limit save siem log disable/enable property recording the logs can be stopped and then started again manually log in to the single connect gui navigate to siem configuration click the “options” drop down menu button of the log configuration select “disable” or “enable” siem log monitoring log in to the single connect gui, navigate to siem configuration, open the “monitoring” tab, enter in fields to filter, and search