Setting up rsyslog servers using the Web UI

Prev Next

Use the View and add Rsyslog servers section on the RSYSLOG tab of the Notification settings page to add and configure rsyslog servers.

All_RsyslogSettings_scap.png
To add an rsyslog server:
  1. Click the Settings tab.

  2. Click Notifications on the side bar.

  3. Click the RSYSLOG tab.

  4. Click Add Rsyslog server. The Add new Rsyslog server dialog box opens.

  5. Enter the name of the rsyslog server to receive the notifications (for example, NX7400) in the Server Name box.

  6. Enter the IP address of the rsyslog server in the IP Address box.

  7. Select the Enabled checkbox to choose which servers will receive rsyslog notifications.

  8. Select the delivery frequency in the Delivery drop-down list box:

    • Default—Use the delivery frequency specified in the Default delivery box in the Rsyslog Settings area.

    • Per Event—Send a notification each time a malware object is detected.

  9. Select the event type or All Events in the Notification drop-down list box to send rsyslog notifications when the specified events are detected.

  10. Select CEF, LEEF, CSV, XML, JSON, or Text as the default format and select which level of detail (only for XML, JSON, or text) is provided in the Format drop-down list box. Select Default to use the format specified in the Default format box in the Rsyslog settings section.

    • Normal—This format contains detailed information and abstracts, such as alert type, ID, source IP, malware name, hostname, and alert URL without redundant information.

    • Concise—This format contains basic information, such as alert type, ID, source IP, malware name, hostname, and alert URL.

    • Extended—This format contains detailed information and abstracts, including data-theft information (if any) and static-analysis details. This format provides all details about files and objects modified during analysis.

  11. Select the severity classification for the rsyslog notification in the Send as box:

    • Default—Use the value specified in the Default send as field in the Rsyslog Settings area.

    • Alert—Action must be taken immediately (severity 1).

    • Critical—Critical conditions (severity 2).

    • Debug—Debug-level messages (severity 7).

    • Emergency—Emergency: system is unusable (severity 0).

    • Error—Error conditions (severity 3).

    • Informational—Informational messages (severity 6).

    • Notice—Normal but significant conditions (severity 5).

    • Warning—Warning conditions (severity 4).

  12. Select UDP or TCP in the Protocol drop-down list box.

  13. Click Add new Rsyslog Server.

To update the rsyslog servers:
  1. Click the Settings tab.

  2. Select Notifications on the side bar.

  3. Click the RSYSLOG tab.

  4. Click the server in the Name column of the View and add Rsyslog Servers section.

  5. Click the icon in the Edit column.

  6. Update settings as needed.

  7. Click Update Rsyslog server.

To enable or disable an rsyslog server:
  1. Click the Settings tab.

  2. Select Notifications on the side bar.

  3. Click the RSYSLOG tab.

  4. Select the checkbox for the server.

  5. Click Enable or Disable.

  6. Click Yes to confirm the action.

To remove an rsyslog server:
  1. Click the Settings tab.

  2. Select Notifications on the side bar.

  3. Click the RSYSLOG tab.

  4. Select the checkbox for the server.

  5. Click Remove.

  6. Click Yes to confirm the action.