Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
AngeloP
Participant

Some Audit Logs are not sent to SIEM when using dedicated log server

Hi,

 

I noticed that some audit logs are sent to the siem while others aren't when using dedicated log servers, for example - if the operation is "Incident Viewed", "Set Object", "Delete Object", so basically the least important audit logs, then the Origin Log servers is the dedicated Log Server and the logs are sent to the SIEM.

 

But if the Operation is "Publish", "Delete Rule", "Create Rule" or "IPS Update" Than the Origin Log Server is usually the SMS itself and these audit logs are not being sent to the SIEM (as only the dedicated servers are sending the logs).

 

I would like to send with log exporter all the audit logs to the siem even when using dedicated log servers, including those where the Origin log server IP is the SMS itself, as they contain info about important changes being made to IPS and access control configuration. How can that be done?

0 Kudos
3 Replies
PhoneBoy
Admin
Admin

I believe you can configure Log Exporter on the SMS in this case to export the relevant logs directly (assuming they are there).

0 Kudos
AngeloP
Participant

Thanks for the reply, so if I understand correctly, the log exporter should be configured both on the dedicated log servers and on the SMS, but the SMS should be configured to only send Audit logs in this case, as not to duplicate logs sent to the SIEM?

 

Is there a one liner command for log exporter to only export audit logs or does it require manipulation of the file targetConfiguration.xml?

0 Kudos
PhoneBoy
Admin
Admin

The Log Server and the SMS should have different logs, thus there shouldn't be any overlap.
That said, I believe you can just configure Log Exporter to send audit logs.

0 Kudos