Prerequisite: You must have saved the syslog server details successfully in the Syslog page.
Steps:
To access the Syslog page from the Manager tab, do the following.
Click the Manager tab.
From the Domain drop-down list, select the domain you want to work in.
Select Setup → Notification → IPS Quarantine Access Events.
Option
Definition
Enable Syslog Logging?
Select Yes to enable syslog and No to disable syslog.
Applicable Admin Domains
Current — Refers the admin domain currently selected. This is enabled by default.
Children — Refers the child admin domains of the current domain.
Target Syslog Server Name or IP Address
The IP address or name of the syslog server which becomes the destination of the alert notifications sent by all devices.
Note
The length of server name has been increased to support up to 255 characters from 40 characters.
Target Syslog Server UDP Port
Port on the target syslog server that is authorized to receive syslog messages.
The default protocol for syslog forwarding from Sensors is UDP. Therefore, this port must not be altered.
Syslog Facility
Standard syslog prioritization value. The choices are as follows:
Security/authorization (code 4)
Security/authorization (code 10)
Log audit (note 1)
Log alert (note 1)
Clock daemon (note 2)
Local user 0 (local0)
Local user 1 (local1)
Local user 2 (local2)
Local user 3 (local3)
Local user 4 (local4)
Local user 5 (local5)
Local user 6 (local6)
Local user 7 (local7)
Syslog Priority
You can map each severity (Informational, Low, Medium, or High) to one of these standard syslog severities:
Emergency – System is unusable
Alert – Action must be taken immediately
Critical – Critical conditions
Error – Error conditions
Warning – Warning conditions
Notice – Normal but significant condition
Informational – Informational messages
Debug – Debug-level messages
Message Body
System default — The default message is a quick summary of an event.
Customized — Personalized message of an event.
Important
Till 11.1 Update 4 release, all Syslog notifications generated from the Manager UI were prefixed with the timestamp format MMM DD HH:MM:SS. From the 11.1 Update 5 release onwards, along with this timestamp, additional timestamp with format [MMM DD, YYYY HH:MM:SS] is appended to each Syslog notification from the Manager for auditing purposes. This timestamp update is independent of the syslog variables (default or customized) used to configure syslog notifications.
As a user, you need to update the Syslog parsing logic in the third-party Syslog application(s) in use to avoid any timestamp conflicts in the Syslog notifications.
Click Test Connection in the page.
Click Edit in the Message Body field in the page.
The Customize Syslog Forwarder Message page displays.
Customize the format for the syslog forwarder message.
Option
Definition
Message
Form the message by typing in the required text and by clicking on the parameters provided below this field.
Important
For Syslog information to appear correctly, ensure that you use the dollar-sign ($) delimiter immediately before and after each element. Example: $SENSOR_NAME$
Save
Saves the message you created. Displays the IPS Quarantine Access Events page when you click.
Cancel
Cancels the changes you made to the message.
Reset to System Default
After you customize the syslog message, the Reset to System Default button appears in the Customize Syslog Forwarder Message page. Click this button to revert to the system default message.
Click Save.