Hello All,
I have a server that has two distinct types of Syslogs. The system syslogs are already being fed into SIEM over the standard port 514.
I figured no big deal, I can send the other data source over a non-standard port.
However, when I go to set this up, the drop down for the port selection only gives me one option, 514. Is there a way to add more ports here or another work around which will let me setup unique data sources from the same server?
Solved! Go to Solution.
perhaps you can use TLS port, just don't check for validity. or have a look under the ERC interface comms tab, to see if you can specify more than one port for syslog.
perhaps you can use TLS port, just don't check for validity. or have a look under the ERC interface comms tab, to see if you can specify more than one port for syslog.
sssyyy is correct, you need to go to the receiver properties and add more ports to the syslog port list.
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA