Skip to main content
Skip table of contents

Configure a Device or Host for Syslog Collection

  1. On the main toolbar, click Deployment Manager.
  2. Click the System Monitors tab.
  3. If needed, add Host Records for the Syslog receiving system and the Syslog sending system. These may be the same device.

    You can select an Origin or Impacted Host as the Known Host from a log returned in search results. For more information see Monitor, Search, and Analysis.
  4. Do one of the following:
  5. Direct the syslog generating device to send its syslog information to the Syslog receiving System Monitor Agent.

    See the device's documentation.
  6. Accept the new Agent in the System Monitors tab. For more information, see Agent Identification and Acceptance.
    From the System Monitors tab, the agent can be viewed in the upper grid.
    1. Right-click the selection, click Actions, and then click Accept.
    2. Click OK.
  7. Enable the Syslog Server on the System Monitor Agent.
    1. From the System Monitors tab, double-click the agent.
    2. Click the Syslog and Flow Settings tab.
    3. Select the Enable Syslog Server check box.
    4. (Optional) Add the Syslog Relay hosts and Syslog Relay regular expressions.

      The regex is case sensitive.

    5. (Optional) Click Advanced and edit the Syslog Server Advanced Agent Properties.
    6. Click OK.
    The Log appears in the Log Sources tab in the New Log Sources grid with a status of Pending.
  8. Configure the Log Source with the appropriate Log Source Type and Log Processing Policy. Then, accept the new Syslog Log Source. For more information, see Log Sources.
  9. Verify that the Syslog traffic is being received using Investigator or Tail.
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.