Configuring a Cilasoft QJRN/400 Log Source
JSA automatically discovers and creates a log source for syslog events that are forwarded from Cilasoft QJRN/400.
These configuration steps are optional.
- Log in to JSA.
- Click the Admin tab.
- Click the Log Sources icon.
- Click Add.
- In the Log Source Name field, type a name for your log source.
- From the Log Source Type list, select Cilasoft QJRN/400.
- From the Protocol Configuration list, select Syslog.
If Cilasoft QJRN/400 is configured to write events to the integrated file system with the *IFS option, the administrator must select Log File, and then configure the log file protocol.
- Learn more about syslog protocol parameters:
Log Source Identifier
Enter the IP address as an identifier for events from your Cilasoft QJRN/400 installation.
The Log Source Identifier must be unique value.
Select the Enabled check box to enable the log source.
By default, the check box is selected.
Select the Credibility of the log source. The range is 0 - 10.
The credibility indicates the integrity of an event or offense as determined by the credibility rating from the source devices. Credibility increases if multiple sources report the same event. The default is 5.
Target Event Collector
Select the Target Event Collector to use as the target for the log source.
Select this check box to enable the log source to coalesce (bundle) events.
By default, automatically discovered log sources inherit the value of the Coalescing Events list from the System Settings in JSA. When you create a log source or edit an existing configuration, you can override the default value by configuring this option for each log source.
Incoming Event Payload
From the list, select the Incoming Event Payload encoder for parsing and storing the logs.
Store Event Payload
Select the Store Event Payload check box to enable the log source to store event payload information.
By default, automatically discovered log sources inherit the value of the Store Event Payload list from the System Settings in JSA. When you create a log source or edit an existing configuration, you can override the default value by configuring this option for each log source.
- Configure the protocol values.
- Click Save.
- On the Admin tab, click Deploy Changes.