Syslog are not visible at the SIEM
search cancel

Syslog are not visible at the SIEM

book

Article ID: 267230

calendar_today

Updated On:

Products

ProxySG Software - SGOS

Issue/Introduction

Syslog logs configured properly:

  • Select the Administration tab > Event Logging > Syslog LogHosts 
  • Click on the Add Loghost button.  Enter the domain name or IP address of your log host server in the Loghost field and click on the OK button.
  • Check the Enable Syslog check box and click Apply

Are not visible at the backend SIEM

Environment

Release : Any

Cause

The syslog is generated and sent as soon as the event occurs.

As far as the setup is done properly it should work, there are not registered bugs at any time for the same.

Resolution

Take capture on port 514 while performing some changes or forcing some event to occur for the syslog to register it. 

The capture should display the packets the proxy is sending to the SIEM

Additional Information