Log forwarding to other NLS or SIEM
Posted: Thu Mar 30, 2017 4:01 am
Hello,
in our testing scenario we are trying to forward logs from one NLS1 to second NLS2. This test should verify whether we will be able to send logs to corporate LogRhytm collector through NLS.
Practically I want to see syslog messages from linux and network devices (arriving to default port 5544 on NLS1) and windows event logs (arriving to NLS1:3515) in NLS2 in correct parsed records.
I tried simple udp output, but it converted event logs to syslogs and they were not parsed correctly. How should I set filters and output to get this working?
Thank you,
Michal
in our testing scenario we are trying to forward logs from one NLS1 to second NLS2. This test should verify whether we will be able to send logs to corporate LogRhytm collector through NLS.
Practically I want to see syslog messages from linux and network devices (arriving to default port 5544 on NLS1) and windows event logs (arriving to NLS1:3515) in NLS2 in correct parsed records.
I tried simple udp output, but it converted event logs to syslogs and they were not parsed correctly. How should I set filters and output to get this working?
Thank you,
Michal