Deep Discovery Director - Network
Analytics (the appliance)
uses Deep Discovery
Inspector's detection data for
analysis and correlation. Therefore, you must configure Deep Discovery
Inspector to send syslogs to the
appliance.
To perform this task, you must first access the appliance's Settings screen and record the
syslog IP address and port number, then log on to Deep Discovery
Inspector and use the recorded information
to add the appliance as a syslog server.
Procedure
-
Perform on Deep Discovery Director - Network Analytics
- Log on to Deep Discovery Director and access the Settings screen.
- Go to and record the syslog IP address and port number.You can change the syslog port number if desired.
- Close the Settings screen.
-
Perform on Deep Discovery Inspector.
- Log on to the Deep Discovery Inspector console.
- Go to .
- Click Add.The Add Syslog Server screen appears.
Add Syslog Server - Select Enable syslog server.
- In Server name or IP address and Port, type the
IP address and port number identified in Step 2 above.The default Deep Discovery Director - Network Analytics syslog port is 514.
- Configure the following:
Field Value ProtocolTCPFacility levellocal3The facility level specifies the source of a message.Syslog severity level InformationalThe syslog severity level specifies the type of messages to be sent to the syslog server. Deep Discovery Inspector will send informational and above messages.Log format Trend Micro Event Format (TMEF)Specifies the format with which to send event logs to the syslog server. Trend Micro Event Format (TMEF) is the format used by Trend Micro products for reporting event information.Logs to send to the syslog server - Select all logs in the
Detection logs
section.
Note
Do not select logs in the System event logs section.
- Select all logs in the
Detection logs
section.
- Select Connect through a proxy server to use the settings configured on to connect to a syslog server.Select this option if Deep Discovery Inspector requires the use of proxy servers for intranet connections.
- Click Save.
- Log out of the Deep Discovery Inspector console.