The Sophos Astaro Security Gateway DSM for IBM
QRadar accepts events by using
syslog, enabling QRadar to
record all relevant events.
About this task
To configure syslog for Sophos Astaro Security Gateway:
Procedure
- Log in to the Sophos Astaro Security Gateway console.
- From the navigation menu, select .
- Click the Remote Syslog Server tab.
The Remote Syslog Status window is
displayed.
- From Syslog Servers panel, click
the + icon.
The Add
Syslog Server window is displayed.
- Configure the following parameters:
- Name - Type a name for the syslog
server.
- Server - Click the folder icon
to add a pre-defined host, or click + and type
in new network definition
- Port - Click the folder icon
to add a pre-defined port, or click + and type
in a new service definition.
By default, QRadar communicates
by using the syslog protocol on UDP/TCP port 514.
- Click Save.
- From the Remote syslog log selection field,
you must select check boxes for the following logs:
- POP3 Proxy - Select this check
box.
- Packet Filter - Select this check
box.
- Packet Filter - Select this check
box.
- Intrusion Prevention System -
Select this check box
- Content Filter(HTTPS) - Select
this check box.
- High availability - Select this
check box
- FTP Proxy - Select this check
box.
- SSL VPN - Select this check box.
- PPTP daemon- Select this check
box.
- IPSEC VPN - Select this check
box.
- HTTP daemon - Select this check
box
- User authentication daemon -
Select this check box.
- SMTP proxy - Select this check
box.
- Click Apply.
- From Remote syslog status section,
click Enable
You can now configure the log source in QRadar.
- To configure QRadar to
receive events from your Sophos Astaro Security Gateway device: From
the Log Source Type list, select Sophos
Astaro Security Gateway.