SIEM, Vulnerability Scanning, Server Monitoring and Compliance Training for IT Professionals
Table of Contents

Syslog Consolidation Template

Syslog consolidation is the process of saving real-time syslog entries to a Data Provider, also known as a Log Database.

By default, syslog messages are automatically saved to the Log Database. For more information see: Syslog Server Settings

Tutorials

Centralized Syslog Management (Part 2: Consolidation)

How to configure syslog consolidation:

Server Manager comes pre-installed with a Syslog Consolidation template that automatically saves syslog messages to the Log Database. You have the option of extending this template or creating your own.

  • From the Explorer View, expand Templates | Sample Templates | Log Consolidation then right click on Syslog Consolidation and select Template Properties.
  • The Template Properties view contains 4 tabs.

The Options Tab

  • Optionally assign a Consolidation filter to dump entries you do not want saved to the Log Database. When assigned, only entries that pass the assigned consolidation filter are saved to the Log Database.
  • Use the Log Entry Retention Policy drop-down to select the retention policy. The retention policy is another template that defines the number of days to retain in the Primary and Archive Log Databases, for example, archive entries older than 30 days and retain entries for 150 days for a total of 180 days. Assign multiple retention policies to remove entries that match filter criteria defined in each retention policy. For more information see: Log Entry Retention Policy Template

Related Topics

Data Provider

Log Consolidation Templates

Log Entry Retention Policy Template

Data Providers

Syslog Server Settings

Syslog