enVision 3.5.x
TCP
collection
The setup for syslog over TCP is on the syslog collector configuration screen. Select Overview > System Configuration > Services > Manage Collector Service then select the appropriate site/Node link, this will display the main details about the syslog collection and at the end of the details is a line for TCP Information (this may be collapsed so look at the right hand side for the expand/collapse icon).
The RFC (Reliable Delivery for syslog at http://www.ietf.org/rfc/rfc3195.txt) suggests the well known port syslog-conn 601/TCP although use of this is optional and (as an example) a default Cisco PIX configuration uses 1468/TCP.
After selecting the listener port number you click the Add button to enter the IP addresses of devices which will use this facility. Also, as you may find in a variety of notes in the internet about syslog over TCP, you need to specify a delimiter for the different messages as (unlike UDP) it will not always be one message per single packet. Use the default delimiter initially and then review the results before assuming that any alteration in the settings is required.
Setting up an enVision system to allow syslog over TCP does not stop the UDP collection and the system will read from both TCP and UDP at the same time.
Note: There is an option sometimes added to Linux known as syslog-ng which has d_tcp configured as the syslog destination which may also be another TCP device used to send syslog data as well as Cisco PIX
Related Articles
RSA Authenticator 4.5 for iOS and Android Quick Start Guide (German) 5Number of Views Log Configuration Parameters 43Number of Views How to configure which events the Logging Server records 10Number of Views Audit event REVIEW_DEFNITION is misspelled in RSA Identity Governance & Lifecycle 20Number of Views Monitoring scripts delayed when sent to remote syslog 27Number of Views
Trending Articles
RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide How to Upgrade Internal SHA-1 Certificates to SHA-256 in Authentication Manager Using rsautil RSA Authentication Manager 8.9 Setup and Configuration Guide RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows