> For the complete documentation index, see [llms.txt](https://docs.blusapphire.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.blusapphire.io/log-forwarding/03_log-forwarding-guide/log-forward/darktrace.md).

# DarkTrace

## Configuring DarkTrace IDS Syslog &#x20;

To configure Darktrace to send Syslog to the BluSapphire Log Collector, you must be a Darktrace administrator with access to the user interface. &#x20;

1\. Log in to the Darktrace interface. &#x20;

2\. Expand the top left menu and select Admin, a second menu appears. &#x20;

3\. Select the System Config page.&#x20;

![](https://firebasestorage.googleapis.com/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MMRHZBPHlLDUc8519fX%2Fuploads%2F0OczJyPyhbzxsvNptnzl%2Ffile.jpeg?alt=media)

4\. In the “Alerting” section, click the Verify Alert Settings button. &#x20;

5\. In “JSON Syslog Alerts,” set the field to True. &#x20;

6\. Set the JSON Syslog server to the IP address of the “Log Collector”. &#x20;

7\. Set the JSON Syslog server port \<port>. Check Appendix A for default port.&#x20;

8\. Set “JSON Syslog TCP Alerts” to True.&#x20;

![](https://firebasestorage.googleapis.com/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MMRHZBPHlLDUc8519fX%2Fuploads%2FhGO1SsGWaxM7gUiFCK5s%2Ffile.jpeg?alt=media)
