cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1174
Views
0
Helpful
5
Replies

NetWitness Syslog push from Ironport ESA

TuereTurner
Level 1
Level 1

I am trying to send syslogs to NetWitness from the ironport ESA.

 

There doesn't seem to be a firewall issue... we are ale to telnet from the on 514 to the syslog server.

When this command is ran a record shows in  Netwitness ,but no ironport text mail logs are showing up.

 

We are using TCP and the facility is mail.

 

 

How can I confirm the clustered ironport  ESA's are sending the logs to Netwitness?

 

 

5 Replies 5

Did you set up a log subscription?


Yes the log subscription was created.


Here's a link I found to Netwitness docs related to Cisco ESA... might be helpful?



https://community.rsa.com/api/core/v3/contents/25748/data?v=2




So I used this doc to configure the log subscription .

 

It's pretty straight forward.

 

Is there anyway for me to trouble shoot the syslog push to Netwitness.

 

Maybe a grep on system logs?

 

 

I don't have any syslog pushes, so I don't see anything in my system logs... so maybe?



Do you have the option to rollover a syslog push? That might kick it?

Otherwise maybe a packet capture?