How can enVision 4.1 send Syslog messages to a remote syslog server
After configuring the Syslog Managed Output Action with source and destination IP and MAC addresses on port 514/udp and restarted the Alerter Service, messages are not getting to the remote syslog. However, when I click on the Test button, test messages are successfully reaching the remote server. Event sources are actively sending messages to enVision. What am I missing? Thanks!
Firstly, welcome to the forums, and above all, thank you for being an RSA customer.
Please consider moving this question as-is (no need to recreate) to the proper forum for maximum visibility. Questions written to the users' own "Discussions" space don't get the same amount of attention and can go unanswered for a long time.
You can do so by selecting "Move" under ACTIONS along the upper-right. Then search for and select: "RSA enVision"
Alert messages are sent when an event is triggered.
In my opinion you should extract the logs data in batch with lsdata and thus sending it to a remote syslog by a script.
It seems more convenient to use enVision and forward the syslog data it's already receiving from various event sources. Thanks.
Sent from Guy's iPad
I guess simple forwarding doesn't work, but did you have a look at EDI Service?
You would need a batch job or similar to syslog-forward the exported events, but I guess that could work.