FireEye
FireEye
To Forward Fireeye Logs
Log in to the FireEye appliance by using the CLI.
To activate configuration mode, type the following commands:
enable
configure terminal
To enable rsyslog notifications, type the following command:
fenotify rsyslog enable
To add BluSapphire Log Collector as a rsyslog notification consumer, type the following command:
fenotify rsyslog trap-sink blus
To specify the IP address for the “Log Collector” system that you want to receive rsyslog trap-sink notifications, type the following command:
fenotify rsyslog trap-sink blus address <Log Collector_IP_address>
To define the rsyslog event format, type the following command:
fenotify rsyslog trap-sink blus prefer message format cef
To save the configuration changes to the FireEye appliance, type the following command:
write memory
Last updated