To enable syslog forwarding for fault notification, do the following:
Task
-
Select
Manager → <Admin Domain Name>
→ Setup
→ Notification
→ Faults
→ Syslog (same for Central Manager).
The Syslog window is displayed.
-
Fill in the following fields:
Field Description Enable Syslog Notification Yes is enabled; No is disabled Admin Domain Select the below options to enable admin domain notification: - Current— Send notifications for alerts in the current domain. Always enabled for current domain.
- Children— Include alerts for all child domains of the current domain.
Note
This field is not present for Central Manager.
Server Name or IP Address Type either the Host IP Address or Host Name of the syslog server where alerts will be sent. For Host IP address, you can enter either IPv4 or IPv6 address.
Note
The length of server name has been increased to support up to 255 characters from 40 characters.
Port Port on the target server which is authorized to receive syslog messages. The standard port for syslog, 514, is pre-filled in the field. Facilities Standard syslog prioritization value. The choices are as follows: - Security/authorization (code 4)
- Security/authorization (code 10)
- Log audit (note 1)
- Log alert (note 1)
- Clock daemon (note 2)
- Local user 0 (local0)
- Local user 1 (local1)
- Local user 2 (local2)
- Local user 3 (local3)
- Local user 4 (local4)
- Local user 5 (local5)
- Local user 6 (local6)
- Local user 7 (local7)
Severity Mapping You can map each fault severity (Informational, Error, Warning, and Critical) to one of the standard syslog severities listed below (default severity mappings are noted in parentheses): - Emergency— System is unusable
- Alert— Action must be taken immediately
- Critical— (HIGH) Critical conditions
- Error— Error conditions
- Warning— (MEDIUM) Warning conditions
- Notice— (LOW) Normal but significant condition
- Informational— (INFORMATIONAL) Informational messages
- Debug: Debug-level messages
Forward Faults Select the severity of the faults that you want to be forwarded to the syslog server. The options are: - Critical— Only Critical faults
- Error and above— Both Error and Critical faults
- Warning and above— Warning, Error, and Critical faults
- Informational and above— All faults
-
Click
Save.
Note
You must click Save before you will be able to customize the message format sent to your syslog server.
-
Select the
Message Preference to send as the syslog forwarding message. The choices are:
- System Default— The default message is a quick summary of a fault with two fields for easy recognition: Attack Name and Attack Severity. A default message reads:
Attack $IV_ATTACK_NAME$ ($IV_ATTACK_SEVERITY$) - Customized— Create a custom message. To create a custom message, do the following:
- Click Edit to create a custom message.
- Type a message and select (click) the parameters for the desired alert identification format. The following figure displays a custom message. You can type custom text in the Message field as well as click one or more of the provided elements below the field box.
- Click
Save when finished to return to the Syslog page. The Customized button is automatically selected after you have customized the
Message Preference.
Caution
For syslog information to appear correctly, ensure that you use the dollar-sign ($) delimiter immediately before and after each element. Example: $ATTACK_TIME$
Syslog variables for fault notification Syslog variable name Description $IV_ACK_INFORMATION$ Displays additional acknowledgment information when a created fault is acknowledged after the hysteresis period. $IV_ADDITIONAL_TEXT$ Displays additional text for the raised fault. $IV_ADMIN_DOMAIN$ Name of the domain. $IV_DESCRIPTION$ Description of the fault. $IV_DEVICE_NAME$ Name of the device. $IV_FAULT_COMPONENT$ The component for which the fault is generated. $IV_FAULT_LEVEL$ Displays the fault level (Manager system level, Sensor level, or Sensor interface level) $IV_FAULT_NAME$ The name of the fault. $IV_FAULT_SOURCE$ Indicates if the fault is generated by the Manager or sent by the Sensor. $IV_FAULT_TIME$ The time at which the fault is generated. $IV_FAULT_TYPE$ Indicates if the event is created, acknowledged, or cleared. $IV_MEMBER_DEVICE_NAME$ Name of the Sensor. $IV_OWNER_ID$ ID of the Manager or the Sensor. $IV_SEVERITY$ The severity of the fault (critical, error, or warning).
- System Default— The default message is a quick summary of a fault with two fields for easy recognition: Attack Name and Attack Severity. A default message reads:
- Click Save.