These instructions explain how to add and accept NetMon as a new log source in LogRhythm Enterprise so that you can receive Syslog on the default port (514). For instructions on how to configure LogRhythm Enterprise and NetMon for a non-default Syslog port, see Settle Syslog Port to Non-Default Value in LogRhythm Enterprise.
Open the NetMon Web Management interface.
On the top navigation bar, click Configuration, and then click the Syslog tab.
In the Syslog Type field, select TCP.
In the Syslog IP field, enter your System Monitor Agent's IP address.
Click Apply Changes.
In LogRhythm Enterprise
Open the Deployment Manager.
Click the Log Sources tab.
Right-click the pending log source, click Actions, and then click Change Log Source Type.
Select Syslog - LogRhythm Network Monitor.
Right-click the pending log source again, click Actions, and then click Resolve Log Source Hosts.
Right-click the pending log source once more, click Actions, click Accept, and then click Defaults.
Click the Network Monitors tab.
Right-click an empty part of the table, and then click New.
In the Name field, enter a name for the NetMon.
Click the Host icon next to the Host field, select the NetMon host that was created for the log source, and then click OK.
In the Management/API Address field, enter the NetMon's IP address.
In the API Username field, enter your NetMon username—preferably a username with admin privileges.
In the API Key field, enter the full API key of your NetMon. This can be found in NetMon on the Configuration > User page.
Click Test. If all steps have been completed successfully and the Enterprise instance can reach your NetMon, you will see an "Authentication Succeeded" message.