FireEye
FireEye 
To Forward Fireeye Logs
- Log in to the FireEye appliance by using the CLI. 
- To activate configuration mode, type the following commands: 
enable 
configure terminal 
- To enable rsyslog notifications, type the following command: 
fenotify rsyslog enable 
- To add BluSapphire Log Collector as a rsyslog notification consumer, type the following command: 
fenotify rsyslog trap-sink blus 
- To specify the IP address for the “Log Collector” system that you want to receive rsyslog trap-sink notifications, type the following command: 
fenotify rsyslog trap-sink blus address <Log Collector_IP_address> 
- To define the rsyslog event format, type the following command: 
fenotify rsyslog trap-sink blus prefer message format cef 
- To save the configuration changes to the FireEye appliance, type the following command: 
write memory 
Last updated
