Register syslog servers

Prev Next

You can enable ePO - On-prem to synchronize with your syslog server. A syslog is a way for network devices to send event messages to a separate logging server. For example, you can use syslog to collect information about specific threat events.

You must have the domain name or IP address for your syslog server. To know how to create a syslog server, see KB87927.

ePO - On-prem syslog forwarding only supports the TCP protocol, and requires Transport Layer Security (TLS). For more information, see KB91194.

  1. Select MenuConfigurationRegistered Servers, then click New Server.

  2. From the Server type menu on the Description page, select Syslog Server, specify a unique name and any details, then click Next.

  3. From the Registered Server Builder page, configure these settings:

    1. Server name — Use DNS-style domain names (for example, internaldomain.com) and fully qualified domain names or IP addresses for servers. (for example, server1.internaldomain.com or 192.168.75.101)

    2. TCP port number — Type the syslog server TCP port. The default is 6514.

    3. Enable event forwarding — Click to enable event forwarding from Agent Handler to this syslog server.

    4. Test — Click Test Connection to verify the connection to your syslog server.

  4. Click Save.

After you register the syslog server, you can set ePO - On-prem to send events to your syslog server. This log file includes any syslog server errors that might occur.