Configuring syslog integration

You can integrate IBM® Guardium® Exposure Manager with a syslog server to collect and provide events to a security information event management (SIEM) platform for analysis of potential security and threat incidents. You can create policies to send an alert to syslog when a violation occurs.

Procedure

  1. From the main menu, click Management hub > Integrations.
  2. On the Integrations page, click the Discover tab, and then click the Syslog logging protocol (syslog) card.
  3. In the About step of the Connect to Syslog wizard, read the information, and then click Next.
  4. In the Configure step of the Connect to Syslog wizard, enter the following syslog configuration details, and then click Test connection to ensure that IBM Guardium Exposure Manager can connect to the syslog server.
    Table 1. Syslog integration parameters
    Parameters Description
    Name Enter a unique name for the integration.
    Host Enter the syslog host name.
    Port Enter the port number for the syslog host.
    Transfer protocol Select the transfer protocol you want to use for syslog integration. UDP is the default protocol.
    Formatting options Select any of the following formatting options that you want to use for syslog integration.
    • Use Default to provide Pipe-Separated Values (PSV) file format.
    • Use QRadar LEEF to provide Pipe-Separated Log Event Extended Format (LEEF). QRadar LEEF provides QRadar with additional information to route the syslog events correctly.
    • Use OCSF to provide JSON-based schema. Open Cybersecurity Schema Framework (OCSF) uses a structured, JSON-based schema that's standardized across vendors and works best over TCP or HTTP(S).
  5. After testing the connection, click Finish to save the syslog configuration and create the integration.

Results

You successfully created an integration of a syslog server with IBM Guardium Exposure Manager.