For the complete documentation index, see llms.txt. This page is also available as Markdown.

Syslog Collector applet

The Syslog Collector applet on a Broker VM enables you to collect Syslog data from an external source:

Syslog Collector applet
Description

How to activate Syslog Collector?

How to ingest logs from a Syslog receiver?

Links to content pack/integration details

The Syslog content pack enables automated issue creation by acting as a Syslog server for incoming logs, while also allowing the platform to act as a Syslog client to send messages and mirror investigation activities to external Syslog destinations. It contains the following integrations:

  • Syslog Sender: Use this integration to send messages in RFC 5424 message format and mirror incident War Room entries to Syslog. It includes the mirror-investigation, send-notification, and syslog-send commands.

  • Syslog v2: Use this integration to act as a long-running Syslog server, supporting RFC3164, RFC5424, and RFC6587 formats, which enables automatically opening issues from Syslog clients. This integration is configured using parameters such as Port mapping, Certificate, Private Key, and a Message Regex Filter for issue creation.

Last updated

Was this helpful?