Errors when configuring RSA Access Manager to send logs to RSA enVision or a generic syslog server
Originally Published: 2019-07-24
Article Number
Applies To
RSA Version/Condition: 6.2.x
Issue
Instructions to configure that feature are in the "Installation and Configuration Guide" for your RSA Access Manager server version. For example, in the Access Manager Server 6.2.4 Installation and Configuration Guide, the instructions are in chapter 18 "Integrate With enVision", section "Configure Access Manager Server Using Syslog" on page 345.
There are problems with two of the steps in those instructions in all v6.2.x Installation and Configuration Guide manuals.:
- The SecurCare Online website URL given in step 2 is no longer available.
- The conversion pattern that is given in step 4 is incorrect. If used as shown in the manual, the server fails with the following error message when Access Manager runs (note the misspelling of the word "pattern"):
log4j:ERROR Unexpected char [R] at position 2 in conversion pattern
Cause
- The RSA website "SecurCare Online" has been replaced with a new site, "RSA Link".
- The conversion pattern in step 4 has a percent sign (%) specified where it should not be in front of the word "RSAAXM".
Resolution
- In step 2, download the three files aserver_log4j.conf, eserver_log4j.conf, and dispatcher_log4j.conf files from: RSA NetWitness Event Source Additional Downloads for RSA Access Manager. An RSA Link login is required to be able to access that page. Only those three *_log4j.conf files on that page are needed to configure an Access Manager Server using syslog, so any other files on that page should be ignored.
- In step 4, the correct ConversionPattern instruction setting is:
log4j.appender.A1.layout.ConversionPattern=RSAAXM-4-<ServerInstance> Name: %m%n
The other settings for log4j.appender.A1.SyslogHost and log4j.appender.file.File are correct as shown in the manual.
Related Articles
Forward syslog messages in RSA Authentication Manager 8.0 through 8.3 233Number of Views How to send Operating System logs in /var/log/messages file to a remote syslog server in RSA Authentication Manager 8.6 o… 247Number of Views How to configure RSA Authentication Manager 8.1, 8.2, 8.3 to send data to multiple remote syslog servers 1.79KNumber of Views How to configure SNMP for RSA Authentication Manager 8.x 1.29KNumber of Views Monitoring scripts delayed when sent to remote syslog 27Number of Views
Trending Articles
RSA Authentication Manager 8.9 Setup and Configuration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager 8.9 Release Notes (January 2026) Configure RSA Authentication Manager as a Secure Proxy Server for Cloud Access Service RSA Authentication Manager Upgrade Process
Don't see what you're looking for?