To set up rsyslog servers, perform the following subtasks:
Add the rsyslog servers
Configure the rsyslog servers
Enable the CLI configuration mode:
hostname > enablehostname # configure terminalEnable rsyslog notifications:
hostname (config) # fenotify rsyslog enableSpecify the name of the rsyslog server (for example, AX5400) to receive the notification:
hostname (config) # fenotify rsyslog trap-sink sink_nameSpecify which servers will receive rsyslog notifications (one server per command):
hostname (config) # fenotify rsyslog trap-sink sink_name enableSpecify the IP address or DNS address of the rsyslog server to send event logs to:
hostname (config) # fenotify rsyslog trap-sink sink_name address ip addressSave the configuration:
hostname (config) # write memory
Enable the CLI configuration mode:
hostname > enablehostname # configure terminalEnable rsyslog notifications:
hostname (config) # fenotify rsyslog enableSpecify that an rsyslog notification is sent each time a malware object is detected:
hostname (config) # fenotify rsyslog trap-sink sink_name prefer message delivery per-eventSpecify the format for rsyslog notifications:
Note
The json_legacy-concise, json_legacy-extended, and json_legacy-normal formats are deprecated.
To send notifications in the Common Export Format (CEF), enter:
hostname (config) # fenotify rsyslog trap-sink sink_name prefer message format cefTo send notifications in the comma-separated values (CSV) format, enter:
hostname (config) # fenotify rsyslog trap-sink sink_name prefer message format csv
To send notifications in the Log Extended Event Format (LEEF) (default), enter:
hostname (config) # fenotify rsyslog trap-sink sink_name prefer message format leefTo send notifications in XML Concise format containing basic information such as alert type, ID, source IP, malware name, hostname, and alert URL, enter:
hostname (config) # fenotify rsyslog trap-sink sink_name prefer message format xml-concise
To send notifications in XML Extended format containing detailed information and abstracts including data-theft information (if any) and static-analysis details (XML Extended provides all details about files and objects modified during analysis.), enter:
hostname (config) # fenotify rsyslog trap-sink sink_name prefer message format xml-extended
To send notifications in XML Normal format containing detailed information and abstracts such as alert type, ID, source IP, malware name, hostname, and alert URL without any redundant information, enter:
hostname (config) # fenotify rsyslog trap-sink sink_name prefer message format xml-normalTo send notifications in JSON Concise format containing basic information such as alert type, ID, source IP, malware name, hostname, and alert URL, enter:
hostname (config) # fenotify rsyslog trap-sink sink_name prefer message format json-conciseTo send notifications in JSON Extended format containing detailed information and abstracts including data-theft information (if any) and static-analysis details (JSON Extended provides all details about files and objects modified during analysis.), enter:
hostname (config) # fenotify rsyslog trap-sink sink_name prefer message format json-extendedTo send notifications in JSON Normal format containing detailed information and abstracts such as alert type, ID, source IP, malware name, hostname, and alert URL without any redundant information, enter:
hostname (config) # fenotify rsyslog trap-sink sink_name prefer message format json-normalTo send notifications in Text Concise format containing basic information such as alert type, ID, source IP, malware name, hostname, and alert URL, enter:
hostname (config) # fenotify rsyslog trap-sink sink_name prefer message format text-conciseTo send notifications in Text Extended format containing detailed information and abstracts including data-theft information (if any) and static-analysis details (Text Extended provides all details about files and objects modified during analysis.), enter:
hostname (config) # fenotify rsyslog trap-sink sink_name prefer message format text-extended
To send notifications in Text Normal format containing detailed information and abstracts such as alert type, ID, source IP, malware name, hostname, and alert URL without any redundant information, enter:
hostname (config) # fenotify rsyslog trap-sink sink_name prefer message format text-normal
Specify the severity classification for the rsyslog notification:
Note
Trellix recommends setting the severity classification to
alert.To indicate that action must be taken immediately (severity 1), enter:
hostname (config) # fenotify rsyslog trap-sink sink_name prefer message send-as alertTo indicate that the notification contains critical conditions (severity 2), enter:
hostname (config) # fenotify rsyslog trap-sink sink_name prefer message send-as critTo indicate that the notification contains debug-level messages (severity 7), enter:
hostname (config) # fenotify rsyslog trap-sink sink_name prefer message send-as debugTo indicate an emergency (the system is unusable) (severity 0), enter:
hostname (config) # fenotify rsyslog trap-sink sink_name prefer message send-as emergTo indicate that the notification contains error conditions (severity 3), enter:
hostname (config) # fenotify rsyslog trap-sink sink_name prefer message send-as errorTo indicate that the notification contains informational messages (severity 6), enter:
hostname (config) # fenotify rsyslog trap-sink sink_name prefer message send-as infoTo indicate normal but significant conditions (severity 5), enter:
hostname (config) # fenotify rsyslog trap-sink sink_name prefer message send-as notice
To indicate that the notification contains warning conditions (severity 4), enter:
hostname (config) # fenotify rsyslog trap-sink sink_name prefer message send-as warning
Specify the protocol used to send rsyslog notifications (UDP is the default):
To select UDP, enter:
hostname (config) # fenotify rsyslog trap-sink sink_name protocol UDPTo select TCP, enter:
hostname (config) # fenotify rsyslog trap-sink sink_name protocol TCP
Save the configuration:
hostname (config) # write memory