Symantec Encryption Management Server
The Symantec Encryption Management Server DSM for JSA collects syslog events from Symantec Encryption Management Servers.
Symantec Encryption Management Server is formerly known as Symantec PGP Universal Server.
JSA collects all relevant events from the following categories:
Administration
Software updates
Clustering
Backups
Web Messenger
Verified Directory
Postfix
Client logs
Mail
Whole Disk Encryption logs
Before you can integrate Symantec Encryption Management Server events with JSA, you must configure Symantec Encryption Management Server to communicate with JSA.
Configuring Symantec Encryption Management Server to communicate with JSA
Enable external logging to forward syslog events to JSA.
n a web browser, log in to your Encryption Management server's administrative interface.
Click Settings.
Select the Enable External Syslog check box.
From the Protocol list, select either UDP or TCP.
By default, JSA uses port 514 to receive UDP syslog or TCP syslog event messages.
In the Hostname field, type the IP address of your JSA Console or Event Collector.
In the
Port
field, type514
.Click Save.
The configuration is complete. The log source is added to JSA as Symantec Encryption Management Server events are automatically discovered. Events that are forwarded to JSA by the Symantec Encryption Management Servers are displayed on the Log Activity tab of JSA.
Syslog Log Source Parameters for Symantec Encryption Management Servers
If JSA does not automatically detect the log source, add a Symantec Encryption Management Servers log source on the JSA Console by using the Syslog protocol.
When using the Syslog protocol, there are specific parameters that you must use.
The following table describes the parameters that require specific values to collect Syslog events from Symantec Encryption Management Servers:
Parameter |
Value |
---|---|
Log Source Name |
Type a name for your log source. |
Log Source Description |
Type a description for the log source. |
Log Source Type |
Symantec Encryption Management Server |
Protocol Configuration |
Syslog |
Log Source Identifier |
Type the IP address or host name for the log source as an identifier for events from the Symantec Encryption Management Server. |