Receive Syslogs from a Cisco switch #12152
-
If I wanted to receive syslogs from a Cisco switch how would I go about doing it? Right now I have the logs being forwarded to my standalone manager node at 10.0.80.225. Would I need to open the firewall host groups for syslog up for the switch address? I am just a little confused and need some clarification since what I thought does not work. Let me know if you need more information. Thanks ahead of time all! |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 3 replies
-
Yes, you need to allow syslog traffic from your cisco switch to the manager. https://docs.securityonion.net/en/2.4/firewall.html#configuration |
Beta Was this translation helpful? Give feedback.
Correct, you add to syslog hostgroup, you can also hit the button at the top under 'options' labled 'synchronize grid' to apply the changes to your grid. (Otherwise it takes about 15 minutes for the next highstate to run and changes to apply in the background)
Give it a few minutes, but if the switch is sending syslog data you should see it. You can use the SOC dashboard 'Syslog' to view syslog data