Add a maximum of three syslog servers.
Procedure
- Go to .
- Click Add.The Add Syslog Server screen appears.
- Select Enable syslog server.
- Type the server name or IP address and the port number of the syslog server.Trend Micro recommends using the following default syslog ports:
-
UDP: 514
-
TCP: 601
-
SSL: 6514
-
- Select a facility level.The facility level specifies the source of a message.
- Select a syslog severity level.The syslog severity level specifies the type of messages to be sent to the syslog server.
Syslog Severity Levels
LevelSeverityDescription0Emergency-
Complete system failure
Take immediate action.1Critical-
Primary system failure
Take immediate action.2Alert-
Urgent failures
Take immediate action.3Error-
Non-urgent failures
Resolve issues quickly.4Warning-
Error pending
Take action to avoid errors.5Notice-
Unusual events
Immediate action is not required.6Informational-
Normal operational messages useful for reporting, measuring throughput, and other purposes
No action is required.7Debug-
Useful information when debugging the application.
Note
Setting the debug level can generate a large amount of syslog traffic in a busy network. Use with caution. -
- Select the format to send event logs to the syslog server.
-
CEFCommon Event Format (CEF) is an open log management standard developed by Micro Focus ArcSight. CEF comprises a standard prefix and a variable extension that is formatted as key-value pairs.
-
LEEFLog Event Extended Format (LEEF) is a customized event format for IBM® QRadar® Security Intelligence Platform. LEEF comprises an LEEF header, event attributes, and an optional syslog header.
-
Trend Micro Event Format (TMEF)Trend Micro Event Format (TMEF) is the format used by Trend Micro products for reporting event information. Deep Discovery Advisor uses TMEF to integrate events from various Trend Micro products.
-
- Select the logs to send to the syslog server.
- Select Connect through a proxy server to use the settings configured on to connect to a syslog server.Select this option if you require the use of proxy servers for intranet connections.
- Click Save.