Configure syslog settings

Prev Next

The syslog mechanism transfers events over the syslog channel to Security Information and Event Management (SIEM) or a logging server.

You can configure up to two external syslog server to which the following information are sent based on your configuration:

  • Analysis Results (Malicious only or All)

  • CPU Utilization (above a threshold percentage)

  • Memory Utilization (above a threshold percentage)

  • HDD Utilization (above a threshold percentage)

  • Interface Status

  • User Login/Logout

  • Audit Log

  • HTTPS Session Log

Once the user-defined threshold limit exceeds for CPU Utilization, Memory Utilization and HDD Utilization, syslog events are generated and sent to SIEM receiver. Minimum threshold level supported is 30%. Maximum threshold level supported is 90%. By default, the threshold percentage displayed under Syslog Setting page is 75%.

Whenever the interface link goes down or comes up, syslog events are generated and sent to SIEM receiver.

Analysis results and logon/logoff events are sent to the SIEM receiver.

Note

After syslog events are generated and sent to SIEM receiver, the information are parsed and sent to ESM. The summary is then displayed on the ESM user interface.

Note

The SIEM receiver and ESM can be on separate appliances or can be together in a virtual environment.

  1. Log on to the Intelligent Sandbox web interface.

  2. Click ManageTIS ConfigurationSyslog, then select Enable Logging.

  3. In the Statistic to Log section, make these selections and entries as per requirement.

    • Select Analysis Results, then select a level from the Severity Level drop-down list.

    • Select CPU Utilization and specify the threshold level in the respective Threshold drop-down.

    • Select Memory Utilization and specify the threshold level in the respective Threshold drop-down.

    • Select HDD Utilization and specify the threshold level in the respective Threshold drop-down.

    • Select Interface Status to receive information regarding interface link status.

    • If you want to store the logon/logoff information with a time stamp, select User Login/Logout.

    • Select Audit Log to view logs for administrative actions performed on Intelligent Sandbox. Audit Log is selected by default.

    • Select HTTPS Session Log to view logs for every session established or terminated.

      This option is only available when Common Criteria Mode is enabled in Advanced Security Settings.

      Note

      When HTTPS Session Log is enabled, Intelligent Sandbox web performance is impacted.

  4. From the drop-down, select the communication protocol between your Syslog server and Intelligent Sandbox.

    Note

    If you select TCP/TLS Encryption, then ensure that you upload a valid root CA certificate. You can upload the certificate from ManageSecurityManage CertificatesTrusted CA certificate. For more information see the Upload certificates topic.

  5. You can configure up to two syslog servers on Intelligent Sandbox. To configure the System Log Server options, do the following:

    1. Enable Syslog.

    2. Type the IP address or hostname of the logging server.

      Note

      In CC mode, hostname validation is done based on the logging server certificates. The communication will fail if there is a discrepancy between the hostname of the logging server and the certificate.

    3. Type the port number on which the logging server is listening.

    4. Enable Validate Syslog Server Certificate, to perform security checks on the syslog server certificates.

      Note

      • This checkbox is available only if you chose TCP/TLS Encryption in the communication protocol.

      • This option must be enabled to run Intelligent Sandbox in CC mode. Intelligent Sandbox validates your syslog server certificate before it starts communicating with your syslog server. Intelligent Sandbox will notify you if there was a validation failure.

  6. Click Test Connection. When the "Test connection successful" message appears, click OK.

    Note

    When you select UDP as the Protocol from the drop-down list then Test Connection tab is disabled as UDP uses a simple connectionless transmission model rendering the connection status, unverifiable.

  7. Click Submit.