02-27-2019 10:21 AM
I am trying to send syslogs to NetWitness from the ironport ESA.
There doesn't seem to be a firewall issue... we are ale to telnet from the on 514 to the syslog server.
When this command is ran a record shows in Netwitness ,but no ironport text mail logs are showing up.
We are using TCP and the facility is mail.
How can I confirm the clustered ironport ESA's are sending the logs to Netwitness?
02-27-2019 10:40 AM
02-27-2019 10:46 AM
02-27-2019 11:00 AM
02-27-2019 11:39 AM
So I used this doc to configure the log subscription .
It's pretty straight forward.
Is there anyway for me to trouble shoot the syslog push to Netwitness.
Maybe a grep on system logs?
02-27-2019 12:22 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide