We're migrating from 1200R gateways to 1595R gateways and have syslog configured to send system logs back to our SIEM. With the 1200R gateways, we would get a system message about once every hour or so with a message like this:
"05 23 2025 07:00:45 10.X.X.X <SYSD:NOTE> 2025 May 23 07:00:45 1200R-FW daemon.notice ntpdate[23250]: adjust time server 192.X.X.X offset 0.017780 sec"
We have alerts on the SIEM that trigger if the log source stops sending and it was working fine with the 1200R and we would set the alarm to trigger after 1-2 hours. With the 1595R gateways, the NTP daemon seems to operate differently and we're not getting any system level syslog events to help the SIEM understand if the log source is alive or not.
Is there a way to force NTP to work similar to the 1200R was and trigger a system log and/or is there another method that could be set to just trigger any system level event every X minutes?