Forwarding logs to an external server
Starting with version 8.0, you can forward system logs to an external log management server. System logs (syslog) contain event and notification messages in a specific format. Forwarding the appliance syslogs to an external log management server provides system administrators a centralized location for viewing logs and for further analysis and troubleshooting. The following log servers are supported:
HP ArcSight
Splunk
Access appliances use the Rsyslog client to forward logs. In addition to HP ArcSight and Splunk, other log management servers that support the Rsyslog client can also be used to receive syslogs from the appliance.
To secure the log transmission from the appliance to the log management server, you can use the TLS (Transport Layer Security) option. The Access Appliance currently supports only TLS Anonymous Authentication for log forwarding.
You must use the Veritas Access command-line interface to set up log forwarding. Use the Report> syslog commands on the Access command-line interface to set up the log forwarding. For more details, see the Veritas Access Command Reference Guide.
You can view the configured settings for an appliance node by using the show log-forwarding command. The following details are displayed:
IP address of the log management server.
Port number of the log management server.
Protocol used for forwarding the logs to the log management server.
Time interval in minutes for forwarding logs. The options are 0, 15, 30, 45, or 60. The default is 15. If the interval is set to 0, appliance continuously forwards syslogs to the log management server.
Whether TLS is enabled for secure log transmission.