Our infrastructure team is currently sending all of their device logs to enVision but they would like some of the logs to be sent to their own logging solution as well. Some of the devices only allow one syslog server destination so I am attempting to setup enVision to relay the syslog events after enVision processes the events.
I've already setup a Correlation Rule that matches on the devices by Device Group membership with an Event Selection as Content from ALL devices IN * . The Decay Time is set to 0 Hours. I then have a View that includes the Correlation Rule with an Output Action type of Syslog.
The result I'm seeing is that not all of the events are getting forwarded to their syslog server. I'm stumped on this one and haven't been able to get any debug information out of pi_alerter.exe.
Any help or best practices for setting up enVision as a SYSLOG relay would be appreciated.
It would probably be much easier to set up a box with syslog-ng and have it do the relaying for you.
Depending on the device types you need to relay, setup is very simple. The docs and knowledgebase have information on the settings you need to use for your relay. The only devicetype we had some challenges with was Oracle -- there's a thread here with info on making that work.