Views:
The syslog response action enables you to specify a Syslog server where Active Responder sends events when a response is triggered.
Note: Before you set up a Syslog action, a UDP Syslog agent must be running on the Syslog destination IP and port configured for this action.

Procedure

  1. Review Create or edit a response action.
  2. Select Syslog from the Action Type list.
  3. Click Syslog Settings (or click Next), and then enter the following information:
    • IP Address of Server (UDP) — IP address of the syslog server.
    • Port — Listening port on the syslog server (0-65535). The default setting is 514.
    • Facility — Choose the syslog facility that applies.
    Important
    Important
    To implement this action, you must add it to an Active Responder policy. Learn more.