cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
kotman
Level 7
Report Inappropriate Content
Message 1 of 6

Audit Log syslog

Jump to solution
Audit Logs can we have a syslog method? Is there an article with that?
1 Solution

Accepted Solutions
Former Member
Not applicable
Report Inappropriate Content
Message 4 of 6

Re: Audit Log syslog

Jump to solution

Hello @kotman 

Thanks for your response.

Audit logs or any other logs are not forwarded by ePO to the Syslog receiver only threat events .

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

View solution in original post

5 Replies
Former Member
Not applicable
Report Inappropriate Content
Message 2 of 6

Re: Audit Log syslog

Jump to solution

Hello @kotman 

Thanks for your post.

Yes, You can configure a Syslog Server.

Use the below KB article:

https://kc.mcafee.com/corporate/index?page=content&id=KB87927

https://kc.mcafee.com/corporate/index?page=content&id=KB91194

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

kotman
Level 7
Report Inappropriate Content
Message 3 of 6

Re: Audit Log syslog

Jump to solution

Hello Vivs,

With syslog, we can send threat logs with event ids. McAfee ePO Audit Logs have no event id. Can we send only audit logs as syslog?

Best Regards

Former Member
Not applicable
Report Inappropriate Content
Message 4 of 6

Re: Audit Log syslog

Jump to solution

Hello @kotman 

Thanks for your response.

Audit logs or any other logs are not forwarded by ePO to the Syslog receiver only threat events .

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

TLAY
Level 7
Report Inappropriate Content
Message 5 of 6

Re: Audit Log syslog

Jump to solution

I know this is old, but I can confirm this.  The only way we could figure out how to pull required logs is to either:

a) Log on to the console directly and execute reports (or view existing dashboards)

b) Use a tool which is capable of hooking in to the database and pulling information based off of SQL provided from an applicable report.

For things like successful or failed logins, it would be tolerable if logs were at the least in flat files on the system.  But they are not. So chalk one up to making something easy, hard.

To paraphrase my parents, I am not upset it is like this, but it is disappointing.

cdinet
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 6 of 6

Re: Audit Log syslog

Jump to solution

You can also easily create a query for audit events, then run a server task periodically that runs that query and can email the report to anyone.

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community