To enable communication between the Syslog server and the Manager, perform the following tasks:
Create a user account in the Manager
Configure Syslog events in the Manager
Create a user account in the Manager
The Syslog server communicates with the Manager using a user account available in the Manager. You should create a user account in the Manager. To create a user in the Manager, login to the Manager MariaDB and create a user. This user can connect remotely to the Manager from the specified Syslog server. You should grant SELECT permissions to the user on the database.
Run the following commands on the MariaDB command prompt:
GRANT SELECT ON lf.* TO 'user_name'@'receiver_ip_address' IDENTIFIED BY 'user_name_password' WITH GRANT OPTION;This command creates the user and sets the required privileges. In the command,
user_nameis the desired username,user_name_passwordis the password for the newly created user, andreceiver_ip_addressis the IP address of the Syslog server that will connect to the Manager.FLUSH PRIVILEGES;
This command applies the privilege changes without restarting MariaDB.
Configure Syslog events in the Manager
For information on configuring Syslog events in the Manager, see the Trellix Intrusion Prevention System Product Guide.