Configuring a Log Source
To integrate ForeScout CounterACT with JSA, you must manually create a log source to receive policy-based syslog events.
JSA does not automatically discover or create log sources for syslog events from ForeScout CounterACT appliances.
- Log in to JSA.
- Click the Admin tab.
- On the navigation menu, click Data Sources.
- Click the Log Sources icon.
- Click Add.
- In the Log Source Name field, type a name for your log source.
- In the Log Source Description field, type a description for the log source.
- From the Log Source Type list, select ForeScout CounterACT.
- Using the Protocol Configuration list, select Syslog.
- Configure the following values:
Table 1: Syslog Protocol Parameters
Parameter
Description
Log Source Identifier
Type the IP address or host name for the log source as an identifier for events from your ForeScout CounterACT appliance.
- Click Save.
- On the Admin tab, click Deploy Changes.
The log source is added to JSA.