03-19-2018 10:26 AM - edited 03-08-2019 07:34 PM
We have two Cisco IronPort ESA C190s on OS 10.0.1-087.
Our Security team has a requirement that we begin pushing syslogs to our SIEM device (Logrythm). Our team currently pushes syslogs to our infrastructure management collector (Loginsight).
I need to be able to push syslogs to both locations. I don't see a way to do it in the GUI, can it be done via commandline?
The issue is that our team doesn't have access to the security team's SIEM device so I can't use those logs to troubleshoot issues so I need both OR I need verification that only one can be used so they have a compelling reason to grant me access.
Solved! Go to Solution.
03-19-2018 11:02 AM
03-19-2018 10:32 AM
03-19-2018 10:42 AM
Sorry, that didn't answer my question. I need to know how to configure MULTIPLE syslog collectors.
I am well aware of how to configure it to push syslogs in general via the GUI.
03-19-2018 10:47 AM
03-19-2018 10:59 AM
Just to clarify, I can add a second subscription to a log type I already have listed and set it to go to a different syslog location?
Will it create the new log file or do I have to manually give it a different file name?
03-19-2018 11:02 AM
03-19-2018 11:04 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide