Configuring an External Syslog Server
Ivanti Policy Secure(IPS) allows you to send the log data to an external syslog server. You should use syslog if your enterprise has any long-term record-keeping or accounting requirements.
To configure reporting to a syslog server:
- Select System > Log/Monitoring.
- Click the Settings tab.
- Specify the maximum log size and select the events to be logged.
- Specify the server configuration as described below and click Add. You can specify multiple syslog servers.
- Save the configuration.
To enable syslog reporting for each local log category, you must perform this procedure on each local log tab: Events, User Access, Admin Access, and Sensors.
Settings |
Guidelines |
---|---|
Server name/IP |
Specify the fully qualified domain name or IPv4/IPv6 address for the syslog server. NOTE: If you select TLS from the Type list, the server name must match the CN in the subjectDN in the certificate obtained from the server. |
Facility |
Select a syslog server facility level (LOCAL0-LOCAL7). Your syslog server must accept messages with the following settings: facility = LOG_USER and level = LOG_INFO. |
Type |
Select the connection type to the syslog server. You can select:
|
Client Certificate |
(optional) If you select TLS from the Type menu and your remote syslog server requires client certificates, select the installed client certificate to use to authenticate to the syslog server. Client certificates are defined in the Configuration > Certificates > Client Auth Certificates page. Client certificates must be installed on the device before they can be used. There is no fallback if a connection type fails. |
Filter |
Select a filter format. Any custom filter format and the following predefined filter formats are available:
|