RSA Admin

Stopping Syslog Flooding from Impacting Other Syslog Devices

Discussion created by RSA Admin Employee on Aug 5, 2011
Latest reply on Apr 26, 2012 by RSA Admin

I have an RFE ESE-503 submitted for this already but doesn't seem to be any update on it. I was wondering what the community did to prevent one syslog device from taking up 130% of the EPS if it has a misconfiguration issue or a DDoS is launched against it. The issue is logs from other syslog devices will not be collected.

Outcomes