Knowledge base
Breadcrumbs

Syslog (HIAB only)



Purpose

This document provides set up information on the Syslog integration on HIAB.

Introduction

HIAB can pass logs and findings via Syslog events, which work with virtually any other security solution in the market, custom implementation of this with a wide range of SIEMs and event correlations systems among our existing MSSPs and partners already. For example: ArcSight.

Set Up Syslog

To set up Syslog:

  1. Go to Menu > Settings > Integrations.

  2. Select the Syslog tab.

    Integration Settings Syslog.PNG


  3. Provide the below information to use Syslog:

Option

Description

Host

Provide the hostname.

Port

Provide the port that Syslog is using to communicate.

Facility

Choose a facility code from the drop-down menu.

Facility code is used to specify the type of program that is logging the message.

Prefix

Enter any word that you want to add as a prefix for each line.

Protocol

Select one of the protocols from the drop-down menu.

Send audit log

Check this box to receive audit log.

Arcsight

Click on this field to use the ArcSight format.

TLS

Click on this field to encrypt data. Use secure transport layer.

Certificate

Upload the certificate for the Syslog server. Only needed if TLS is enabled.

Certificate uploaded

Displays if any certificate has been uploaded.

Status

Click on this button to check the network connectivity.

Save

Click on this button to save your current settings.

Related Articles