- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
How can enVision 4.1 send Syslog messages to a remote syslog server
After configuring the Syslog Managed Output Action with source and destination IP and MAC addresses on port 514/udp and restarted the Alerter Service, messages are not getting to the remote syslog. However, when I click on the Test button, test messages are successfully reaching the remote server. Event sources are actively sending messages to enVision. What am I missing? Thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Firstly, welcome to the forums, and above all, thank you for being an RSA customer.
Please consider moving this question as-is (no need to recreate) to the proper forum for maximum visibility. Questions written to the users' own "Discussions" space don't get the same amount of attention and can go unanswered for a long time.
You can do so by selecting "Move" under ACTIONS along the upper-right. Then search for and select: "RSA enVision"
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Christopher, thank you for the welcome. I moved my question to the RSA enVision forum. Thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi,
waht do you want to do: send the only alert messages to a syslog server or send all messages?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hello IKSSri,
I'd like to send all messages to the remote syslog server.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi,
Alert messages are sent when an event is triggered.
In my opinion you should extract the logs data in batch with lsdata and thus sending it to a remote syslog by a script.
Rgds,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi Uzanatta,
It seems more convenient to use enVision and forward the syslog data it's already receiving from various event sources. Thanks.
Sent from Guy's iPad
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
already got a solution for that?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
No not yet.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
I guess simple forwarding doesn't work, but did you have a look at EDI Service?
You would need a batch job or similar to syslog-forward the exported events, but I guess that could work.
