To sign in, use your existing MySonicWall account. To create a free MySonicWall account click "Register".
I am looking for a way to store the audit logs of the NSA3650 on an external syslog server.
So far I have only found the "Send by mail" function on the NSA.
Does anyone have any tips on how to implement this?
I've not tested this myself but you can give a different Syslog Server Profile ID for the "Configuration Auditing" event group, which should send the events to the dedicated server that handles this "Profile ID". Let me know if that works.
did you try below screenshot about logs settings?
Thanks for this hint!
Syslog is activated and will be send to the syslog server.
Do you know of a way to send only these messages to a syslog server? (the others go to another server)
I had already read that this should work with the "event profile", but unfortunately I can't get any further.
as @MustafaA said that you should create syslog profile and assign to syslog settings.
1) Create syslog profile and assign an id different from 0 (zero)
2) Edit Configuration change under the Syslog settings and assign new syslog event id.
Check "Enhanced audit logging" setting on Management page. You can generate extra log entries with this setting [NOT in the Audit Log section] and this is off by default.
Enhanced audit logging I have already enabled,