Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 

Configuring a Log Source

 

To integrate ForeScout CounterACT with JSA, you must manually create a log source to receive policy-based syslog events.

JSA does not automatically discover or create log sources for syslog events from ForeScout CounterACT appliances.

  1. Log in to JSA.
  2. Click the Admin tab.
  3. On the navigation menu, click Data Sources.
  4. Click the Log Sources icon.
  5. Click Add.
  6. In the Log Source Name field, type a name for your log source.
  7. In the Log Source Description field, type a description for the log source.
  8. From the Log Source Type list, select ForeScout CounterACT.
  9. Using the Protocol Configuration list, select Syslog.
  10. Configure the following values:

    Table 1: Syslog Protocol Parameters

    Parameter

    Description

    Log Source Identifier

    Type the IP address or host name for the log source as an identifier for events from your ForeScout CounterACT appliance.

  11. Click Save.
  12. On the Admin tab, click Deploy Changes.

    The log source is added to JSA.