SIEM, Vulnerability Scanning, Server Monitoring and Compliance Training for IT Professionals
Table of Contents

Syslog Actions

Syslog Actions enable you to write to Syslog messages when executables such as monitors and reports start, trigger, complete, error and recover. Syslog Actions can be also be used to forward triggered log entries to any Syslog server.

Important
When forwarding Syslog messages to another Syslog server, each message's Priority, Facility and Message is applied to the new Syslog message.

To create a Syslog Action

  • From the Menu Bar select File | New. The Create New Object View displays.
  • Select Alerts and Actions. The New Action view displays.
  • Use the Name text box to specify a unique name.
  • From the Type drop-down select Syslog.
  • Use the Syslog server drop-down to select the host you want to write the Syslog Message.
Important
If you do not assign a host, the triggered host is used or if assigned to a report, the localhost is used.
  • Use the Port text box to select the UDP port to write the message on.
  • Use the Facility drop-down to select the Facility.
  • Check the Set priority option then select the priority to apply, otherwise either the executable state (e.g. Started, Warning, Critical, Error, Recovered or Completed) is converted to a Syslog Priority or if forwarding messages, the priority of each message is used.
  • Use Message text box to specify the message you would like to write.
    Use the Variable Variable Button button to specify variables you would like to include in the message (e.g. {HOST}).

Related Topics

Actions

Syslog