Add JSA Log Collector Node to Security Director
Before You Begin
Deploy JSA as a Log Collector.
Configure system log and security logging for the devices managed by Junos Space Security Director from Devices > Security Devices > Modify Configuration.
While adding SRX firewall as a log source in JSA or QRadar, set the log source type to Juniper Junos Platform and not Juniper SRX Series Services Gateway.
You must have the recent version of Juniper Junos Device Support Module (DSM) installed on JSA or QRadar.
After upgrading Log Collector, database password will reset to default credentials, that is, admin/abc123. You must re-configure the database password after Log Collector upgrade before adding the Log Collector node to Security Director.
You must deploy Juniper Secure Analytics (JSA) as a log collector and then add it to Security Director to view the log data in the Dashboard, Events and Logs, Reports, and Alerts pages.
To add Log Collector to Security Director:
To remove an existing Security Director Log Collector and add JSA as a Log Collector:
Select Administration > Logging Management > Logging Nodes.
Select the existing Security Director Log Collector and click the delete icon to delete Security Director Log Collector node.
Click the + icon to add JSA as a Log Collector.
Configure the SRX Series devices to stop sending logs to Security Director Log Collector, and ensure that logs are sent to the JSA node.