This section describes how to send logs from Barracuda SSL VPN to the Comm Broker using syslog.
The SSL VPN has two syslog options, one for the appliance and one for the SSL VPN service. The appliance syslog monitors only appliance-side activity (for example, Apache Web server) where the SSL VPN syslog monitors only the SSL VPN service activity.
The syslog tracks the SSL VPN activity by monitoring the audit logs that are produced. With access to these, the syslog is able to monitor everything that happens on the SSL VPN.
Log in to the SSL VPN as ssladmin.
Navigate to ADVANCED > Syslog.
Set the Use UDP option as required.
In the Syslog Host field, enter the hostname or IP address of the Trellix Comm Broker Sender.
To specify a port, add it in the format of the host entry (FQDN/IPv4 or IPv6 formats).