To establish trust between the syslog client ( NDR appliance) and the syslog server, you need to generate the CA certificates for both server and client, copy the server certificates to the syslog server, and upload client certificates to your NDR appliance.
Generate the following certificates on the syslog server:
CA certificate on syslog server
Certificates for client—rslclient-cert.pem; ca.pem
Certificates for rsyslog server—rslserver-key.pem; rslserver.cert; ca.pem
ca.pem
rslclient-cert.pem
rslclient-key.pem
Copy the ca.pem, rslserver.cert, and rslserver-key.pem certificates to the /etc/pki/tls/private/ path in the syslog server and make changes in the syslog configuration file.
Upload the ca.pem and rslclient-cert.pem certificates to your NDR appliance using the API. See Uploading client certificate to syslog collection .