How To Setup Logging Events to a Syslog Server
search cancel

How To Setup Logging Events to a Syslog Server

book

Article ID: 286708

calendar_today

Updated On:

Products

Carbon Black App Control (formerly Cb Protection)

Issue/Introduction

Setup forwarding of events and logs to an external application.

Environment

  • App Control Console: All Supported Versions

Resolution

  1. Log in to the Console and navigate to Settings > System Configuration > Events.
  2. Click Edit and adjust the External Event Logging section accordingly, please note:
    • The Syslog Address can be specified via IP or FQDN, though FQDN is recommended.
    • The Syslog Port can be customized, but regardless of port UDP will be used.
  3. After changes have been made, click Update and confirm.

Additional Information

  • App Control Server can output in syslog format. Any application that can ingest syslog format should work.
  • Currently it is not possible to:
    • Filter the Events sent from App Control. Filtering should be done in the application ingesting the Events.
    • Use TCP instead of UDP for the network traffic.
  • More information can be found in the User Guide > System Configuration > Event Management Options > Setting up External Event Logging.