Blue Coat Systems ProxySG configuration

Prev Next

This section describes how to send logs from Blue Coat Systems ProxySG using TCP syslog.

Note

This procedure works only if the syslog server (Trellix Comm Broker) supports receiving events using TCP (not UDP).

To send logs from Blue Coat Systems ProxySG:
  1. On the Configuration > Logs tab, define an Access Log file that meets your requirements.

  2. On the Configuration > Upload Client tab, select Custom Client in the Client type field.

  3. Select text file in the Save the log file as field.

  4. (Optional) To reduce the transmission time for log uploads, enter a value as low as 5 seconds in the Send partial buffer after field.

  5. In the Upload Client section, click Settings to open the Custom Client settings dialog box for the Access Log file.

  6. Specify the IP address and TCP port number to point the custom client to the syslog server (the Comm Broker Sender).

  7. On the Configuration > Upload Schedule tab, select continuously in the Upload type section.

  8. Open Visual Policy Manager.

    1. For a Web Access Layer, set a new action to Modify Access Logging.

    2. In the Add Access Logging Object dialog box, select Enable logging to and then select the Access Log file.