Here's a useful link pertaining to understanding syslog data from Unix servers
The link provided above is not working.
But I would like to know is there any way to transport the logs collected by a syslog server to RSA envision.
I have an ES series appliance and therefore can't use a remote collector.
Need to know which syslog server can be used and how to configure RSA to reeive logs messages from syslog server.
We mainly have windows, linux, unix and cisco devices.
Any help would be appreciated.
Yes, there are a number of syslog relays available that can do this. Syslog-NG is probably the most popular of these, but others do exist.
There is a really good page on syslog relays in the enVision help file that describes how to set these up.
IMHO, I think that rsyslog works a little better than syslog-ng when it comes to relay of syslog messages.
Has good information on it and if for some reason you needed support you can get it there as well.