These instructions explain how to add and accept NetMon as a new log source in LogRhythm Enterprise so that you can receive Syslog on the default port (514). For instructions on how to configure LogRhythm Enterprise and NetMon for a non-default Syslog port, see Set Syslog Port to Non-Default Value in LogRhythm Enterprise.
In NetMon
- Open the NetMon Web Management interface.
- On the top navigation bar, click Configuration, and then click the Syslog tab.
- In the Syslog Type field, select TCP.
- In the Syslog IP field, enter your System Monitor Agent's IP address.
- Click Apply Changes.
In LogRhythm Enterprise
- Open the Deployment Manager.
- Click the Log Sources tab.
- Right-click the pending log source, click Actions, and then click Change Log Source Type.
- Select Syslog - LogRhythm Network Monitor.
- Click OK.
- Right-click the pending log source again, click Actions, and then click Resolve Log Source Hosts.
- Right-click the pending log source once more, click Actions, click Accept, and then click Defaults.
- Click the Network Monitors tab.
- Right-click an empty part of the table, and then click New.
- In the Name field, enter a name for the NetMon.
- Click the Host icon next to the Host field, select the NetMon host that was created for the log source, and then click OK.
- In the Management/API Address field, enter the NetMon's IP address.
- In the API Username field, enter your NetMon username—preferably a username with admin privileges.
- In the API Key field, enter the full API key of your NetMon. This can be found in NetMon on the Configuration > User page.
- Click Test. If all steps have been completed successfully and the Enterprise instance can reach your NetMon, you will see an "Authentication Succeeded" message.