Configure an Open Collector Log Source

Accept the Pending Log Source

  1. Open the Client Console Deployment Manager.

  2. Click the Log Sources tab.

    In the New Log Sources grid, a pending log source appears with a name similar to 

    (customerid)-opencollector.c.e3-hub753dd405.internal 

  3. Check the Action check box for this log source.

  4. Right-click and select Actions, Change Log Source Type.

  5. In the text filter box, enter Open Collector.

  6. Select the value System : Syslog - Open Collector.
    Do not select the specific log source types yet. You will do that in a later step.

  7. Right-click and select Actions, Resolve Log Source Host.

  8. Right-click the selection and click ActionsAccept.

  9. Do one of the following:

  10. Click OK.

  11. To see the newly accepted Log Source in the grid, click Refresh.

Apply the Log Source Virtualization Template

  1. Double-click to open the newly accepted Open Collector Log Source.
    The Log Message Source Properties window appears.

  2. Click the Log Source Virtualization tab.

  3. Select the Enable Virtualization checkbox.

  4. Click Create Virtual Log Sources.
    The Create Virtual Log Sources dialog box appears.

  5. In the Log Source Virtualization Template menu, select the log sources you are planning to collect. At this time, LogRhythm Cloud to Cloud collection supports:
    Azure Event HubCarbon BlackCisco AMPDuoGmail Message TrackingOktaPubSubSophos Central

  6. Click Save.
    The confirmation prompt appears.

  7. Click Apply.

  8. Click OK.
    New Log Sources appear in the grid as children of your parent log source.

  9. Click on the System Monitors Tab.

  10. Click on the action box next to the agent named (customerid)-dpwac.

  11. Right-click the selection and click Actions, Service Restart.

After this initial setup, you will be able to start configuring the beats themselves in the Web Console. For more information on specific beats, see .