Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Syslog Configuration (Platform)

Syslog Configuration Overview

You can use the Syslog protocol for auditing and for forwarding anomaly messages to one or more external Syslog servers. Alarms can be generated for use in an NMS alarming environment.

Syslog messages follow Common Event Format (CEF) conventions as shown below:

An example of Syslog messages is shown below:

From the left navigation menu, navigate to Platform > External Services > Syslog Configuration to see configurations. You can create, clone, edit and delete syslog configuration.

Create Syslog Config

  1. From the left navigation menu, navigate to Platform > External Services > Syslog Configuration and click Create Syslog Config (top-right).
  2. Configure the Syslog server.
    • IP Address (or hostname)
    • Port
    • Protocol - UDP, TCP
    • Facility - kern, user, mail, daemon, auth, syslog, lpr, news, uucp, authpriv, ftp, cron, local0, local1, local2, local3, local4, local5, local6, local7
    • Time Zone (optional) (new in version 4.0)
  3. Click Create to save the configuration and return to the list view.
  4. To configure another Syslog server, repeat the steps above.
  5. To enable messages to be sent to a configured server, toggle on Use for Audit and/or Forward Anomalies, as appropriate. (Before version 4.0, messages would include the default aos-server hostname even if the hostname had been changed.)

Edit Syslog Config

  1. From the left navigation menu, navigate to Platform > External Services > Syslog Configuration and click the Edit button for the Syslog configuration to edit.
  2. Make your changes.
  3. Click Update to update the Syslog configuration and return to the list view.

Delete Syslog Config

  1. From the left navigation menu, navigate to Platform > External Services > Syslog Configuration and click the Delete button for the Syslog configuration to delete.
  2. Click Delete Syslog Config to delete the Syslog configuration and return to the list view.