Configuring Blue Coat SG for syslog
To allow syslog event collection, you must configure your Blue Coat SG appliance to forward syslog events to IBM QRadar.
Before you begin
Note: When you send syslog events to multiple syslog
destinations, a disruption in availability in one syslog destination
might interrupt the stream of events to other syslog destinations
from your Blue Coat SG appliance.
Procedure
- Select .
- From the Log list, select the log that contains your custom format.
- From the Client type list, select Custom Client.
- Click Settings.
- From the Settings For list, select Primary Custom Server.
- In the Host field, type the IP address for your QRadar system.
- In the Port field, type 514.
- Click OK.
- Select the Upload Schedule tab.
- From the Upload the access log list, select Continuously.
- Click Apply.