Issue
- Send notifications to your Syslog server from ESET PROTECT On-Prem
- Export Threat events, Firewall Aggregated events, HIPS Aggregated events, Audit events, Enterprise Inspector alert events
Solution
-
Open ESET PROTECT On-Prem in your web browser and log in.
-
Click More → Settings and expand Advanced Settings.
-
In the Syslog Server section:
-
Next to Use Syslog server, click the toggle to enable it.
-
In the Host field, type the IP address or hostname for the destination of Syslog messages.
-
In the Port field, the default value is set to 514.
-
-
In the Logging section, click the toggle next to Export logs to Syslog to enable it and click Save.
-
For a detailed list of the format and meaning of attributes of all exported events (Threat events, ESET Firewall events, HIPS events, Audit events, Enterprise Inspector alert events), visit the Export logs to Syslog Online Help topic.