SYSLOG Profiles

<< Click to Display Table of Contents >>

Navigation:  Sensor Settings > Capture Results Delivery > Setting up the Configurator >

SYSLOG Profiles

Setting up SYSLOG Profiles

SMB profile settings.
Fig. 32. SYSLOG profile settings.

1. Name and status

Profile name:

Administrators can select any profile name that is helpful, meaningful and easy to remember.

Profile is used by default:

Yes means that this profile is used by default.

2. SYSLOG settings

SYSLOG server address:

The IP address or name of the SYSLOG server for results delivery.

Port:

The SYSLOG server port.

TCP:

Allows to use TCP to deliver messages to the SYSLOG server.

Warning!
You can use SSL to send messages to the SYSLOG server only if TCP is enabled.

SSL:

Enable/disable the use of SSL encryption when sending intercepted messages to the server.

Keep connection:

Send messages using the same connection to the server that is receiving messages. If this option is disabled, then each message will be sent via a separate TCP connection.

3. Message format

Script:

The filename of the Lua script, which will be used to prepare the message. The script file must be located in the [INSTALLDIR]\scripts directory.

4. Error handling

Timeout after failure:

Timeout for message delivery in the event of receiver rejection. Provide a value in seconds.

5. For GROUP profiles

Weight:

Determines a ratio for distribution of messages among receivers. Possible values are from 1 to 10 and the setting is valid only when used in a group profile.

Reserve profile:

Enable/disable the use of the reserve profile. If this setting is enabled and the main (non-reserve) delivery profiles fail, this profile will be used for message delivery. The setting is valid only when used in a group profile.