Setting up rsyslog servers

Prev Next

To set up rsyslog servers, perform the following subtasks:

  • Add the rsyslog servers

  • Configure the rsyslog servers

To add an Rsyslog server:
  1. On the Web UI, select the Settings tab.

  2. Select Notifications on the side bar.

  3. Click the RSYSLOG tab to display the View and Add Rsyslog Servers area.

  4. Click Add Rsyslog Server.

  5. Enter the name of the rsyslog server to receive the notifications in the Server Name box and click Add Rsyslog Server.

    EX_AddRsyslogServer_scap.png
  6. Select the Enabled check box to choose which servers will receive rsyslog notifications. Select the Enable All check box to ensure that all listed servers receive rsyslog notifications.

  7. Enter the IP address of the rsyslog server in the IP Address box.

  8. To apply the rsyslog server listing changes, click Add New Rsyslog Server.

To configure the rsyslog servers:
  1. On the Web UI, select the Settings tab.

  2. Select Notifications on the side bar.

  3. Click the RSYSLOG tab to display the View and Add Rsyslog Servers area.

  4. Click the All__edit_icon.PNG icon for the server you want to edit.

  5. Select the delivery frequency in the Delivery drop-down list box:

    • Default—Use the delivery frequency specified in the Default delivery box in the Rsyslog Settings area.

    • Per Event—Send a notification each time a malware object is detected.

  6. Select Malware Object or All Events in the Notification drop-down list box to send rsyslog notifications when malware objects are detected.

  7. Select CEF, LEEF, CSV, XML, JSON, or Text as the default format and select which level of detail (only for XML, JSON, or text) is provided in the Format drop-down list box. Select Default to use the format specified in the Default format box in the Rsyslog Settings area.

    • Normal—This format contains detailed information and abstracts, such as alert type, ID, source IP, malware name, hostname, and alert URL without redundant information

    • Concise—This format contains basic information, such as alert type, ID, source IP, malware name, hostname, and alert URL.

    • Extended—This format contains detailed information and abstracts, including data-theft information (if any) and static-analysis details. This format provides all details about files and objects modified during analysis.

  8. Select the severity classification for the rsyslog notification in the Send as box:

    • Default—Use the value specified in the Default send as field in the Rsyslog Settings area.

    • Alert—Action must be taken immediately (severity 1).

    • Critical—Critical conditions (severity 2).

    • Debug—Debug-level messages (severity 7).

    • Emergency—Emergency: system is unusable (severity 0).

    • Error—Error conditions (severity 3).

    • Informational—Informational messages (severity 6).

    • Notice—Normal but significant conditions (severity 5).

    • Warning—Warning conditions (severity 4).

  9. Select UDP or TCP in the Protocol drop-down list box.

  10. To apply the rsyslog server listing changes, click Update.