These instructions explain how to configure your LogRhythm Enterprise instance to receive Syslog data from a port other than the default (514).
In LogRhythm Enterprise
- Open the Deployment Manager.
- Click the System Monitors tab.
Double-click the Agent that will receive the Syslog output.
The System Monitor Agent Properties window appears.
In the bottom-left corner of the window, click Advanced.
The Agent Advanced Properties window appears.
- In the text filter field under the Name column, type Syslog.
- Specify the SyslogTCPPort that you will be sending to.
- Specify the SyslogUDPPort that you will be sending to.
- Click OK to close the Agent Advanced Properties window, and then click OK to close the System Monitor Agent Properties window.
In NetMon
- Open the NetMon Web Management interface.
- On the top navigation bar, click Configuration, and then click Syslog.
- In the Syslog Type field, select UDP, TCP, or SecureTCP.
- In the Syslog Port field, enter the Syslog port that you configured in LogRhythm Enterprise.
- Click Apply Changes.