Skip to main content
Skip table of contents

Syslog - Epic Hyperspace CEF

Device Details

Vendor

Epic Systems

Device Type

Electronic Healthcare Records

Supported Model Name/Number

N/A

Supported Software Version(s)

Epic 2015-2017

Collection Method

Syslog

Configurable Log Output?

Yes

Log Source Type

Syslog ā€“ Epic Hyperspace CEF

Log Processing Policy

LogRhythm Default

Exceptions

N/A

Additional Information

N/A

Prerequisites

Two Epic Interconnect Custom Message Queues must be setup prior to syslog configuration. See Epic User Auditing Guide for complete steps. (Page 48, Epic User Auditing Guide, Epic 2017)

Device Configuration Checklist

  1. In the Epic Hyperspace user interface, go to Epic System Definitions, Security, Auditing Options, SIEM Syslog Settings, and SIEM Syslog Configuration Options. Then complete the following:
    1. Enter SIEM Host (LogRhythm System Monitor) IP or Hostname.
    2. Enter SIEM Port (Usually port 514 for Syslog).
    3. Set Logging Format to CEF (Common Event Format).
    4. Set Syslog Ending Character to New Line ā€œ\nā€.
    5. Set Check Application Layer Response to Disabled.
    6. Choose how to send record pointers to the SIEM.
      • Hash. SHA-256 Hash Value ā€“ Recommended, Default
      • Keep. Record Pointer as it appears in Epic
      • Delete. Record Pointers not sent
      Record pointers include patient, hospital account and provider records. Hashing or not passing through record pointers can be used as an additional layer of protection for potentially confidential record pointers. It is recommended to use the hash option to have visibility into the Epic environment and retain confidentiality.
    7. (Optional) Set which auditing events are sent to LogRhythm in case of too much traffic.
      1. Edit Events List.
      2. To disable undesired events, press T.
      3. To quit, press Q.
  2. Return to the SIEM Syslog Settings menu.
  3. Select SIEM Syslog and set to Enabled.

Currently Supported Events

Type

STARTUP

LOGIN

FAILEDLOGIN

E_FAILEDPASSWORDCHANGE

E_ADMINPASSWORDCHANGE

E_SELFPASSWORDCHANGE

CONTEXTCHANGE

SECURE

SWITCHUSER

AUTHENTICATION

NATIVE2FACTOR_BYPASS

PHI_CLIENT_FILE

EVENT_LOGGING_ENABLED

EVENT_LOGGING_DISABLED

EW_LOGIN

HKU_LOGIN

HKU_FAILED_LOGIN

CTO_LOGIN

CTO_FAILED_LOGIN

ROVER_LOGIN

ROVER_FAILED_LOGIN

E_HIDDEN_SOURCE_ACCESS_GRANTED

E_HIDDEN_SOURCE_ACCESS_DENIED

ARCHLOG

PUL_SEARCH_AUDIT

AC_BREAK_THE_GLASS_ACCESS

AC_BREAK_THE_GLASS_FAILED_ACCESS

AC_BREAK_THE_GLASS_INAPPROPRIATE_ATTEMPT

MASKED_DATA_DISPLAY

MASKED_DATA_PRINTING

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.