To Forward Fireeye NX Alert Logs
To Forward Fireeye NX Alert Logs
Log in to the FireEye NX using web interface.
Go to Settings > Notifications
Tick rsyslog to enable a Syslog notification configuration.
Enter a name to label your FireEye connection to the “Log Collector” in the Name field.
Click the Add Rsyslog Server button.
Enter the <Log Collector IP Address> in the IP Address field.
Tick the Enabled check box.
Select Per event in the Delivery drop-down list.
Select All Events from the Notifications drop-down list.
Select CEF as the Format drop-down list. Other formats are not supported.
Leave the Account field empty.
Select UDP from the Protocol drop-down list.
Click the Update button.
Last updated