Log Settings Tab Parent topic

TippingPoint Advanced Threat Protection Analyzer maintains system logs that provide summaries of system events, including component updates and appliance restarts. Use the Log Settings tab, in AdministrationIntegrated Products/ServicesLog Settings, to configure TippingPoint Advanced Threat Protection Analyzer to send logs to a syslog server.

Configuring Syslog Settings Parent topic

TippingPoint Advanced Threat Protection Analyzer can forward logs to a syslog server after saving the logs to its database. Only logs saved after enabling this setting are forwarded. Previous logs are excluded.

Procedure

  1. Go to AdministrationIntegrated Products/Services Log Settings.
    The Log Settings screen appears.
  2. Select Send logs to a syslog server.
  3. Type the host name, IPv4 address, or IPv6 address of the syslog server.
  4. Type the port number.
    Note
    Note
    Trend Micro recommends using the following default syslog ports:
    • UDP: 514
    • TCP: 601
    • SSL: 443
  5. Select the protocol to transport log content to the syslog server.
    • UDP
    • TCP
    • SSL
  6. Select the format in which event logs are sent to the syslog server.
    • CEF: Common Event Format (CEF) is an open log management standard developed by HP ArcSight. CEF comprises a standard prefix and a variable extension that is formatted as key-value pairs.
    • LEEF: Log Event Extended Format (LEEF) is a customized event format for IBM Security QRadar. LEEF comprises an LEEF header, event attributes, and an optional syslog header.
    • Trend Micro Event Format (TMEF): Trend Micro Event Format (TMEF) is a customized event format developed byTrend Micro and is used by Trend Micro products for reporting event information.
  7. Select the scope of logs to send to the syslog server:
    • Virtual Analyzer analysis logs
    • Product detection logs
  8. (Optional) Select the logs to exclude from sending to the syslog server.
  9. Click Save.