Design LogRhythm Enterprise for NetMon
To integrate NetMon with LogRhythm Enterprise:
Enable the Syslog Agent:
Log in to the LogRhythm Console.
Open the Deployment Manager.
Click the System Monitors tab.
Double-click the Agent that will receive the Syslog output.
On the Syslog and Flow Settings tab, select the Enable Syslog Server check box.
Click the Advanced button, and then set the SyslogTCPPort to 514. Click OK.
Click OK to close the System Monitor Agent Properties dialog box.
To set the Syslog port to something other than the default 514, see Set Syslog Port to Non-Default Value in LogRhythm Enterprise.
Verify that the Agent is receiving Syslog output:
Click the Log Sources tab.
Click the Refresh icon to refresh Log Sources.
The Pending New Log Source appears with the Log Host Name of the NetMon server.
Double-click the new Log Source.
In the Log Source Acceptance Properties dialog box, change the Log Source Type to Syslog - LogRhythm Network Monitor.
Select the Action check box, right-click the Log Source, click Actions, click Accept, and then click Defaults.
Make sure that log processing settings for NetMon’s Log Source type are set correctly:
Click the Log Processing Policies tab.
Under Log Source Type, search for "Network Monitor."
Double-click the row for Syslog - LogRhythm Network Monitor.
In the MPE Policy Editor dialog box, right-click anywhere in the Rules grid and click Check All.
Right-click again, and then click Properties.
Verify that Disable Automatic Host Contextualization is enabled (a black check mark should appear in the check box), as shown below. Also, verify that the Log should be forwarded as event check box is NOT selected. Click OK.