User Manual Part 5

Administration Tab
SpectraGuard® Enterprise User Guide
251
Under Manage Syslog Severs, click <Add> to open Syslog Configuration dialog where you can add Syslog
server details.
Syslog Configuration Dialog
Syslog Configuration contains the following fields:
Syslog Server (IP Address/Hostname): Specifies the IP address or the hostname of the Syslog server to which
events should be sent.
Note: Configured Syslog servers will use the DNS names and DNS suffixes configured by the user in the Server
Initialization and Setup Wizard on the Config Shell.
Port Number: Specifies the port number of the Syslog server to which the system sends events.
(Default: 514)
Message Format: Specifies the format in which the event is sent, which is Intrusion Detection Message Exchange
Format (IDMEF) or Plain text.
(Default: Plain text)
Note: If you upgrade a server pre-6.2 to 6.6, all previously configured Syslog servers would send events in Plain
text Message Format by default. You can select the IDMEF format by editing the Syslog server settings.
Enabled?: Specifies if the events are to be sent to this Syslog server.
(Default: Enabled)
Click Add to add the details for a new Syslog server.
Editing a Syslog Server
Double-click a row or select a row and click Edit to open Syslog Configuration dialog similar to the one shown above.
Click Save to save all settings.
Deleting a Syslog Server
Select a row and click Delete to discard the details of an existing Syslog server.