S W G U s e r G u i d e
63
Chapter 11: Configuring the Log Server
Â
Having log messages sent to the Syslog
In the
Syslog
Target
tab of the Log Properties screen, do the following for each message type, System
Log, Scanner, and/or Audit, that you plan to send to a Syslog:
1. In the top set of entry fields, on a Facility line, beginning with Facility1, define a facility, as follows:
a. In the
Facility
Mode
field, select a mode label — use this label to differentiate M86 logs from
each other and from other platforms’ logs on the remote Syslog server.
b. In the
Primary
IP
field, specify the Primary Syslog Server target address.
c. In the
Primary
Port
field, specify the Primary port to which the Syslogs will be sent.
d. Optionally, specify the Secondary Syslog Server target address and secondary port, in the
Secondary
IP
field, and
Secondary
Port
field, respectively.
2. In the bottom set of entry fields, for each message type to be sent to the Syslog, select its checkbox,
and select the facility that you defined for it.
3. Continue with
Configuring Scanner Messages sent to a Syslog
.
Â
Configuring Scanner Messages sent to a Syslog
NOTE:
This
procedure
is
relevant
and
mandatory
only
if
you
are
sending
Scanner
messages
to
the
Syslog.
In the
Syslog
Fields
tab of the Log Properties screen, do the following:
1. In the Syslog format, select the format that will be used to present information to the user:
•
Legacy
— Empty fields will not be shown in Syslog messages.
•
Standard
— Empty fields will be shown in Syslog messages
•
ArcSight
— For sites using the external
ArcSight
sever. If you choose this option, you must
configure the IP and Port fields in the
Syslog
Targets
tab with the IP and Port of the
ArcSight
server.
2. Select the syslog transaction fields that should be logged.
3. Do either of the following:
• To have log messages sent to Archive, continue with
Having Web Log messages sent to
Archive
.
• If you have completed Log Configuration, click
Save
, and then if you are ready to distribute
and implement the changes in your system devices, click
.
Â
Having Web Log messages sent to Archive
NOTE:
Ensure
that
the
Send
To:
Archive
checkbox
is
selected
in
the
Logging
Policy
rules
for
logging
information
to
be
sent
to
Archive,
and
that
logging
policy
is
assigned
to
users.
If
a
rule’s
Archive
checkbox
is
not
selected,
its
logging
information
will
not
be
sent
to
archive.
An additional archiving option is to integrate SWG to Security Reporter (SR). For more information
on integrating SWG with SR see
How to connect SWG to Security Reporter via archiving
.
Also,
ensure
that
the
Send
To:
Syslog
checkbox
is
selected
in
the
Logging
Policy
rules
for
log
ging
information
to
be
sent
to
Syslog,
and
that
logging
policy
is
assigned
to
users.
If
a
rule’s
Syslog
checkbox
is
not
selected,
its
logging
information
will
not
be
sent
to
Syslog.
To
verify
that
Send
To:
Syslog
is
selected,
see
To define a rule in a Logging policy
.
To
verify
that
Send
To:
Syslog
is
selected,
see
To define a rule in a Logging policy
.