This URL tests the direct syslog configuration for the Sensor.
Resource URL
PUT /sensor/<sensor_id>/ directsyslog/testconnection
Request Parameters
URL Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Sensor id | Number | Yes |
Payload Request Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Enable logging | Boolean | Yes |
| Inherit settings from parent resource | Boolean | Yes |
| Syslog server IP | String | Yes |
| Syslog server port (UDP) | Number | Yes |
| Syslog facility. Values allowed are:
| String | Yes |
| Attack severity to syslog priority mapping | Object | Yes |
| Message format | String | Yes |
| What attacks to log | Object | Yes |
Details of syslogPriorityMapping:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Informational severity attack mapping. Values allowed are:
| String | Yes |
| Low severity attack mapping. Values allowed are:
| String | Yes |
| Medium severity attack mapping. Values allowed are:
| String | yes |
| High severity attack mapping. Values allowed are:
| String | Yes |
Details of filter:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Log some attacks | Object | Yes |
| Log all attacks - empty object | Object | Yes |
| Log quarantined attacks | Boolean | yes |
Details of LogSomeAttacks:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| The attack definition has syslog notification explicitly enabled | Boolean | Yes |
| Minimum severity of attacks | Object | Yes |
Details of minimumSeverity:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Is minimum severity selected | Boolean | Yes |
| Type of the severity. Allowed values are:
| String | Yes |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
Field Name | Description | Data Type |
|---|---|---|
| Set to 1 if the operation was successful | Number |
Example
Request
PUT https://<NSM_IP>/sdkapi/sensor/1001/directsyslog/testconnection
Payload
{
'enableSyslog': 'true',
'syslogPriorityMapping': {
'lowTo': 'EMERGENCY_SYSTEM_UNUSABLE',
'highTo': 'EMERGENCY_SYSTEM_UNUSABLE',
'informationTo': 'EMERGENCY_SYSTEM_UNUSABLE',
'mediumTO': 'EMERGENCY_SYSTEM_UNUSABLE'
},
'isInherit': 'false',
'serverIp': '10.213.172.94',
'filter': {
'LogSomeAttacks': {
'isExplicitlyEnabled': 'false',
'minimumSeverity': {
'isMinimumSeverity': 'false',
'severityType': 'LOW'
}
}
},
'serverPort': '514',
'syslogFacility': 'SECURITY_AUTHORIZATION_CODE_4',
'message': 'Admin_Domain=$IV_ADMIN_DOMAIN$Alert_Type=$IV_ALERT_TYPE$Attack_Name=$IV_ATTACK_NAME$AttackConfidence=$IV_ATTACK_CONFIDENCE$DetectMech=$IV_DETECTION_MECHANISM$Category=$IV_CATEGORY$SubCategory=$IV_SUB_CATEGORY$INTF=$IV_INTERFACE$Attack_Id=$IV_ATTACK_ID$Attack_Count=$IV_ATTACK_COUNT$Attack_Severity=$IV_ATTACK_SEVERITY$Attack_Signature=$IV_ATTACK_SIGNATURE$Source_Ip=$IV_SOURCE_IP$Dest_Ip=$IV_DESTINATION_IP$Dest_Port=$IV_DESTINATION_PORT$Source_Port=$IV_SOURCE_PORT$Malware_Confidence=$IV_MALWARE_CONFIDENCE$Detection_Engine=$IV_MALWARE_DETECTION_ENGINE$Mal_File_Len=$IV_MALWARE_FILE_LENGTH$Mal_file_md5=$IV_MALWARE_FILE_MD5_HASH$Mal_File_Name=$IV_MALWARE_FILE_NAME$Mal_File_Type=$IV_MALWARE_FILE_TYPE$Mal_Vir_Name=$IV_MALWARE_VIRUS_NAME$Direction=$IV_DIRECTION$Nw_Protocol=$IV_NETWORK_PROTOCOL$AppProtocol=$IV_APPLICATION_PROTOCOL$Attack_Time=$IV_ATTACK_TIME$Qurantine_Time=$IV_QUARANTINE_END_TIME$Result_Status=$IV_RESULT_STATUS$Alert_UUID=$IV_SENSOR_ALERT_UUID$PeerName=$IV_SENSOR_CLUSTER_MEMBER$Sensor_Name=$IV_SENSOR_NAME$SourceOs=$IV_SOURCE_OS$DestOs=$IV_DEST_OS$Src_APN=$IV_SRC_APN$Dest_APN=$IV_DEST_APN$Src_IMSI=$IV_SRC_IMSI$Dest_IMSI=$IV_DEST_IMSI$Src_Phone=$IV_SRC_PHONE_NUMBER$Dest_Phone=$IV_DEST_PHONE_NUMBER$Vlan_ID=$IV_VLAN_ID$'
}Response
{
"status": 1
}Error Information
Following error codes are returned by this URL:
No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
1 | 400 | 1106 | Invalid Sensor |
2 | 404 | 1124 | The Sensor is inactive |
3 | 400 | 6002 | IPV6 is not supported for direct syslog configuration |
4 | 400 | 6002 | Direct syslog is disabled or inherit settings has been selected |