04-01-2004 07:49 AM - edited 03-09-2019 06:56 AM
Hello
is there any supported way to send IDS alerts (4210 running 3 and 4.1) to a remote syslog server? Either through VMS or at the sensor itself ?
thanks
Martin Pfeilsticker
04-07-2004 07:04 AM
As far as my knowledge goes, you cannot send IDS alerts to a remote syslog server.
04-22-2004 01:44 PM
We have had success sending alerts to an remote server by adding its ip address to the sensors Remote Host config on the MC
Then we imported the sensors from the console of the remote syslog server and the alarms poured in
We got much better success recording alarms than with the security monitor
Hope this is helpful
06-04-2004 05:20 AM
Exactly how did you get the sensor to generate syslog messages?
I added the syslog server to the truster hosts, but I don't see any port 514 traffic leaving the sensor (I used tcpdump.)
Are the syslog messages coming directly from the sensor or the VMS server?
Thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide