The syslog response action enables you to specify a Syslog server where Active Responder
sends events when a response is triggered.
Note: Before you set up a Syslog action, a UDP Syslog agent must be running on the Syslog
destination IP and port configured for this action.
Procedure
- Review Create or edit a response action.
- Select Syslog from the Action Type list.
- Click
Syslog Settings (or click
Next), and then enter the following information:
- IP Address of Server (UDP) — IP address of the syslog server.
- Port — Listening port on the syslog server (0-65535). The default setting is 514.
- Facility — Choose the syslog facility that applies.
Important
To implement this action, you must add it to an Active Responder policy. Learn more.