Previous Topic: Custom Log Level for Individual LogsNext Topic: Common Event Format Configuration


Syslog Configuration

For each Syslog server, you must specify the following settings. Find these in the Infrastructure, Logging, External Logging, Syslog n policy folders.

Server Name

Enter the IP address or fully qualified domain name of the Syslog server.

Server Port

Specify the port number that the Syslog listens on. By default, Syslog servers use port 514.

Maximum Message Length

Specifies the maximum length (in characters) for log messages copied to a Syslog server. The Syslog protocol defines a maximum length of 1024 characters, but many Syslog servers can accept longer messages.

Client Port

Specifies the port(s) that CA DataMinder uses to send log messages to Syslog server. If required, you can specify a range of consecutive port numbers (such as 510—515) or a comma-separated list of port numbers and ranges (such as 501,505,510—515).

Syslog Protocol

Specifies the format for data transfers to the Syslog server. Choose either:

IETF RFC 3164

All Syslog servers support this protocol.

IETF Syslog Internet Draft Document

Specifies an extension to the RFC 3164 protocol.

We recommend that you choose the RFC 3164 protocol unless you are certain that your Syslog server supports the extension published in the Internet Draft Document.

Message Format: Choose either:
Common Event Format

Choose this option if your Syslog server supports CEF. For example, ArcSight uses CEF. If you do choose CEF, some further policy configuration is needed; see the next section.

Unformatted Data

If your Syslog server does not support CEF, choose this option.