Join the Conversation

To sign in, use your existing MySonicWall account. To create a free MySonicWall account click "Register".

Options

Audit Log Export to Syslog

Hello,

I am looking for a way to store the audit logs of the NSA3650 on an external syslog server.

So far I have only found the "Send by mail" function on the NSA.


Does anyone have any tips on how to implement this?

Greetings Clemens

Category: Mid Range Firewalls
Reply
Tagged:

Best Answer

  • Options
    CORRECT ANSWER
    MustafaAMustafaA SonicWall Employee
    Answer ✓

    Hello @Clemens

    I've not tested this myself but you can give a different Syslog Server Profile ID for the "Configuration Auditing" event group, which should send the events to the dedicated server that handles this "Profile ID". Let me know if that works.


Answers

  • Options
    MitatOngeMitatOnge All-Knowing Sage ✭✭✭✭

    @Clemens


    did you try below screenshot about logs settings?



  • Options
    ClemensClemens Newbie ✭

    Thanks for this hint!

    Syslog is activated and will be send to the syslog server.

    Do you know of a way to send only these messages to a syslog server? (the others go to another server)

    I had already read that this should work with the "event profile", but unfortunately I can't get any further.

  • Options
    MitatOngeMitatOnge All-Knowing Sage ✭✭✭✭

    as @MustafaA said that you should create syslog profile and assign to syslog settings.


    1) Create syslog profile and assign an id different from 0 (zero)

    2) Edit Configuration change under the Syslog settings and assign new syslog event id.


  • Options
    ArkwrightArkwright All-Knowing Sage ✭✭✭✭

    Check "Enhanced audit logging" setting on Management page. You can generate extra log entries with this setting [NOT in the Audit Log section] and this is off by default.

Sign In or Register to comment.