For customizing syslog message, ensure that Enable Syslog Notification is enabled in the page.
Go to, Manager → <Admin Domain Name> → Setup → Notification → Firewall Access Events.
Enter the Server name or IP address.
Enter the port number
Note
The page displays the message: Settings successfully saved.
Note
In Message body, the default option is selected as Customized.
After configuring the syslog forwarder, do the following steps to customize syslog message.
Click Edit.
The Customize Syslog Forwarder Message page is displayed. By default, the following audit information parameters are included in Messages:
audit action
audit result
audit time
These parameters are displayed as: Audit $IV_AUDIT_ACTION$ $IV_AUDIT_RESULT$ at $IV_AUDIT_TIME$
Type a message and select (click) the parameters that should be included in Message. The following are the list parameters that are available in the Message field.
Syslog variables for audit notificationSyslog variable name
Description
$IV_AUDIT_ACTION$
The audit action value based on the action ID that was passed.
$IV_AUDIT_RESULT$
Indicates the stage of auditing (received, succeeded, failed, or ongoing).
$IV_AUDIT_TIME$
Time stamp of the audit message.
$IV_AUDIT_MESSAGE$
The audit message.
$IV_AUDIT_USER$
The username for the audit.
$IV_AUDIT_CATEGORY$
The action taken for the audit.
$IV_AUDIT_DOMAIN$
Name of the domain.
$IV_AUDIT_DETAIL_COMMENT$
Displays committed comments if the audit details are available.
$IV_AUDIT_DETAIL_DELTA$
Displays audit data if the audit details are available.
Caution
For syslog message to appear correctly, ensure that you use the dollar-sign ($) delimiter immediately before and after each parameter. Example: $ATTACK_TIME$
Click Save to save the customized syslog message.