Adding a domain-level syslog server (required)

Prev Next

To send application-level messages to the Trellix Helix syslog server, you must add a domain-level syslog server to the DSM for each domain for which messages will be sent:

  1. Log on to the DSM as an administrator. Choose either System Administrator or All for the administrator type.

  2. Select to Domains > Switch Domains from the top menu.

    Vormetric 4.png
  3. Select the domain for which you want application-level messages sent to the syslog server.

  4. Click the Switch to domain button.

  5. Select Log > Syslog from the top menu.

  6. Click Add.

  7. Enter information in the following fields to match those set up on the Trellix Helix system:

    • Server Name (for example: tap11206 – should be the Trellix Helix system FQDN or IP address)

    • Transport Protocol

    • Port Number

    • Message Format: Select CEF from the menu.

    Vormetric 5.png
  8. Click OK. Verify the details on the summary screen.

    Vormetric 6.png