McAfee Webgateway - send VRRP events to Syslog Server
Hi, is it possible to sent vrrp events to a remote syslog server (splunk)? Right now we are not aware of any vrrp changes if we do not check the system/messages log.. Would it be possible to send the content of the "messages" file via syslog?
Re: McAfee Webgateway - send VRRP events to Syslog Server
Hi Jon, sorry for the delayed answer.. I configured daemon.info @splunkIP:514 but still do not get any logs into the siem furthermore I found this entry in message log: kernel: Kernel logging (proc) stopped.
If I configure *.* @splunkIP , wouldn't the proxy send all kind of logs to the siem?
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.