Jump to:navigation, search
Wiki































De.png
En.png
Fr.png






Connection of the UTM to a syslog server
Last adaptation to the version: 12.6.0
New:
  • Own Securepoint format for syslog server
  • Note on UDP protocol at PRTG
  • Updated to Redesign of the webinterface
notempty
This article refers to a Resellerpreview

12.5.3.1 12.2.2 11.8

Access: UTM-IP:Port or UTM-URL:Port
Port as configured at Network / Appliance Settings / Webserver
Default-Port: 11115
i.e.: https://utm.ttt-point.de:11115
Default: https://192.168.175.1:11115
Network Appliance Settings  Area Syslog



Syslog settings

Syslog settings
The connection of the UTM is configured on a syslog server (syslogd).
Caption Value Description Appliance Settings UTMuser@firewall.name.fqdnNetwork UTM v12.6 Servereinstellungen Syslog-en.png
Log the UTM hostname in the syslog messages: No In case of Yes activation the hostname is transmitted with

Syslog-Server

Syslog-Server
Add Syslog Server
IP / Hostname: syslog.ttt-point.de IP address or host name of the syslog server.
notempty
If more than one ip-address is assigned to the hostname while you are using Round Robin DNS, the syslog messages may be send to another server each time the service gets restarted. Additionally you won't be protected against DNS Spoofing anymore. Please make sure only one address is assigned to the hostname.
Port: 514Link= Default port for syslog messages
Protocol udp Default protocol for syslog messages.
Alternatively tcp can be selected here.
  • PRTG requires udp as protocol for syslog
  • The Securepoint appliance uses an rfc5424-based protocol format. Alternatively, the following template can be used for syslog servers. This template is automatically recognized by some syslog servers, but must be entered manually for others.

    template rfc5424_and_116_compat_format {template("<${PRI}>1 ${ISODATE} - ${PROGRAM} $(or ${PID} '-') - - ${MSG}\n");};
    <${PRI}>1 ${ISODATE} - ${PROGRAM} $(or ${PID} '-') - - ${MSG}\n



    Securepoint Operation Center (SOC)

    notempty
    The SOC was discontinued on 31.07.2022 and is not compatible with the UTM from v12.6.0.

    Paessler PRTG

    Paessler PRTG can be used to query the syslog data of a UTM.
    Configuration instructions can be found in a separate Wiki article.
    PRTG 1 Startseite.PNG
    Dashboard PRTG