Adding Forwarding Destinations
Before you can configure bulk or selective data forwarding, you must add forwarding destinations.
- On the navigation menu (), click Admin to open the admin tab.
- In the System Configuration section, click Forwarding Destinations.
- On the toolbar, click Add.
- In the Forwarding Destinations window, enter
values for the parameters.
The following table describes some of the Forwarding Destinations parameters.
Table 1: Forwarding Destinations Parameters
Payload is the data in the format that the log source or flow source sent.
Payload is the data in the format that the log source sent.
Normalized is raw data that is parsed and prepared as readable information for the user interface.
Note: JSON data can only be transmitted using the TCP protocol.
The IP address or host name of the vendor system that you want to forward data to.
Use the TCP protocol to send normalized data by using the TCP protocol. You must create an off-site source at the destination address on port 32004.
Note: You cannot transmit normalized and JSON data by using the UDP protocol. If you select the Normalized Event or JSON options, the UDP option in the Protocol list is disabled.
Prefix a syslog header if it is missing or invalid
If a valid syslog header is not detected on the original syslog message and this check box is selected, the prefixed syslog header includes the originating IP address from the packet that JSA received in the Hostname field of the syslog header. If this check box is not selected, the data is sent unmodified.
When JSA forwards syslog messages, the outbound message is verified to ensure that it has a valid syslog header.
- Click Save.
Setting up a forwarding destination does not automatically send data to that destination. You must configure either a routing rule or a custom rule to forward data to the destination.