Procedure
- Go to .The Log Settings screen appears.
- Click Add Detection Syslog.The Add Syslog Server Profile screen appears.
- (Optional) Enable or disable the detection syslog server profile.A new profile is enabled by default.
- Type a profile name.
- Type the host name (FQDN) or IP address of the syslog server.
- Type the port number.
- Select the protocol to be used when transporting log content to the syslog
server.
-
TCP
-
UDP
-
SSL
-
- Select the format in which event logs should be sent to the syslog
server.
-
CEF: Common Event Format (CEF) is an open log management standard developed by HP ArcSight. CEF comprises a standard prefix and a variable extension that is formatted as key-value pairs.
-
LEEF: Log Event Extended Format (LEEF) is a customized event format for IBM Security QRadar. LEEF comprises an LEEF header, event attributes, and an optional syslog header.
-
TMEF (Trend Micro Event Format): Trend Micro Event Format (TMEF) is a customized event format developed by Trend Micro and is used by Trend Micro products for reporting event information.
-
- Click Save.
