Skip to content

v12 integrations: guides for devices that send syslog #2733

Description

@kryonsx

Part of: #2731 · Needs first: #2732 (where the entries live, the shared guide templates and the "View logs" link)

Section numbers in the tables (for example "section 0.4" or "4(c)(7)") point to the research notes. The sections this list relies on are at the bottom of this issue; the others are in #2732.

Why

These devices can already send their logs to the UTMStack Collector as generic syslog (data type syslog, port 7014). Each one needs a card and a guide so customers can see it is supported. Related requests: #1418 (Check Point) and #1263 / #1679 (OPNsense).

Checklist, most valuable first

  • Check Point Quantum (managed gateways, and Quantum Spark) (High): Yes, after a setting on the device
  • WatchGuard Firebox (High): Yes, after a setting on the device
  • Ubiquiti UniFi and EdgeRouter (High): UniFi: Yes, after a setting on the device. EdgeRouter: Yes, after a setting on the device plus the Collector port change for 514 (above)
  • HPE Aruba Networking switches and wireless (High): Yes, after a setting on the device (Instant AP: a port other than 514 not confirmed)
  • Ivanti Connect Secure (High): Yes, after a setting on the device (port change not confirmed)
  • NetScaler ADC and Gateway (formerly Citrix ADC) (High): Yes, after a setting on the device
  • VMware vCenter Server (High): Yes, after a setting on the device
  • Veeam Backup & Replication (High): Yes, after a setting on the app
  • Synology NAS (DSM 7) (High): Yes, after a setting on the device
  • QNAP NAS (QTS, QuTS hero) (High): Yes, after a setting on the device
  • F5 BIG-IP (Medium): Yes, after a setting on the device (UDP, or TCP through the include statement)
  • Juniper SRX firewalls and EX switches (Medium): Yes, after a setting on the device
  • Cisco ISE (Medium): Partly: long messages arrive as several separate logs. Raise Maximum Length as far as the version allows (Cisco documents disagree: 1024 or 8192) …
  • Aruba ClearPass Policy Manager (Medium): Yes, after a setting on the device
  • Barracuda CloudGen Firewall (Medium): Yes, after a setting on the device
  • Zyxel ATP and USG FLEX (Medium): Yes, after a setting on the device
  • OPNsense (Medium): Yes, after a setting on the device
  • SonicWall SMA 1000 and SMA 100 (Medium): Yes, after a setting on the device (SMA 100 port not confirmed)
  • Email security gateways (Cisco Secure Email, Barracuda Email Security Gateway, FortiMail) (Medium): Yes, after a setting on the device
  • NetApp ONTAP (Medium): Yes, after a setting on the device
  • Server management controllers (Dell iDRAC9, HPE iLO 6) (Medium): Yes, after a setting on the device (UDP, or TLS once the Collector has a certificate)
  • Infoblox NIOS (Medium): Yes, after a setting on the device
  • Linux, BSD and Unix hosts without the agent (Medium): Yes, after a setting on the host
  • APC UPS (Network Management Card 2 and 3) (Low): Yes, after a setting on the device
  • Fortinet FortiAuthenticator and FortiNAC (Low): Yes, after a setting on the device

The list in detail

UTMStack steps, the same for every row (sections 0.1 to 0.3):

  1. Install the UTMStack Collector on a Linux host the device can reach, or reuse one.
  2. Enable generic syslog on it: utmstack_forwarder enable-integration syslog tcp (TCP 7014), ... syslog udp (UDP 7014) or ... syslog tls (TLS on TCP 7014, after loading a certificate).
  3. Point the device at <collector host>, port 7014. Prefer TCP: over UDP anything past 2,048 bytes is cut without an error. Over TCP each message must start with <priority> or a length, so pick a normal syslog, CEF or LEEF output, not a "raw" or JSON one.
  4. Check in Log Explorer: dataType is syslog and dataSource is <the device's IP as the Collector sees it>.

The generic parser keeps only log.message (section 0.3), so the filter column can only add a free-text string. It names one only when a vendor sample confirms it; "no confirmed text" means filter on dataSource alone. A device that cannot send to a port other than 514 needs the Collector's UDP syslog listener moved to 514 with utmstack_forwarder change-port syslog udp 514. The command refuses if an enabled integration already listens there, and the four Cisco integrations use UDP 514 by default, so this works only on a Collector without them. (enable-integration syslog 514 udp does not do it: for a built-in data type the port argument is ignored, collectors/forwarder/cmd/enable_integration.go.) The other option is a relay, and then every log shows the relay's address.

Technology Why customers care How its logs reach UTMStack today Works today? Log Explorer filter Priority
Check Point Quantum (managed gateways, and Quantum Spark) Firewall, VPN and threat-prevention events Managed gateways: Log Exporter runs on the Management Server or Log Server, not on the gateway: cp_log_export add name utmstack target-server <collector> target-port 7014 protocol tcp format syslog, then cp_log_export restart name utmstack (it does not start by itself; from R82.10 Check Point recommends mgmt_cli add log-exporter ...). The syslog, cef and leef formats start with a syslog header; the splunk and logrhythm formats may not, so avoid them. Quantum Spark (locally managed): Logs & Monitoring > Log Servers > Syslog Servers > Configure; UDP, or TLS over TCP (no plain TCP); not available while Cloud Services is on. Yes, after a setting on the device dataSource is <Management or Log Server IP> (Log Exporter) or <Spark IP>; text CheckPoint (syslog format; seen only in a Check Point community sample) or Check Point (CEF and LEEF) High
WatchGuard Firebox Firewall, VPN and proxy events Fireware Web UI: System > Logging > Syslog Server tab (cloud-managed: Configure > Devices > Device Configuration > Log Servers). The port can be changed from 514. Format "Syslog" or "IBM LEEF" (no CEF). Up to 3 servers. Transport not confirmed. Yes, after a setting on the device dataSource is <Firebox IP>; text WatchGuard (LEEF format only) High
Ubiquiti UniFi and EdgeRouter Gateway, switch, Wi-Fi and admin events at small sites UniFi Network application: Integration > System Logging / SIEM > "SIEM Server", pick the categories, set IP address and port. Output is CEF only; transport not confirmed. EdgeRouter (EdgeOS): set system syslog host <collector> facility all level <level>, then commit ; save; UDP port 514 only, which Ubiquiti says is "not customizable". UniFi: Yes, after a setting on the device. EdgeRouter: Yes, after a setting on the device plus the Collector port change for 514 (above) dataSource is <IP of the UniFi console that sends>; text UniFi Network High
HPE Aruba Networking switches and wireless Admin logins, port and configuration changes, Wi-Fi events AOS-CX: logging <collector> tcp 7014 severity info (add vrf <name> if needed, and include-auditable-events for audit events). AOS-S and ProCurve: logging <collector> tcp 7014 (ports 1024 to 49151 allowed). Mobility Controller (AOS 8): logging <collector> dest-port 7014 format bsd-standard (UDP). Instant AP: syslog-server <ip>, which has no port option. Yes, after a setting on the device (Instant AP: a port other than 514 not confirmed) dataSource is <switch or controller IP>; no confirmed text High
Ivanti Connect Secure VPN logins; a frequent target of attacks System > Log/Monitoring > Events, User Access and Admin Access tabs > Settings > Syslog Servers (server, facility, Type UDP, TCP or TLS, filter Standard or WELF). Messages follow RFC 5424. TCP and TLS also resend up to 4 hours of logs after an outage. How to set a port other than 514 is not confirmed for Connect Secure. Yes, after a setting on the device (port change not confirmed) dataSource is <gateway IP>; no confirmed text High
NetScaler ADC and Gateway (formerly Citrix ADC) Remote access logins and load balancer events; a frequent target of attacks add audit syslogAction utm_syslog <collector> -serverPort 7014 -logLevel ALL -transport TCP, add audit syslogPolicy utm_syslog_pol true utm_syslog, bind audit syslogGlobal -policyName utm_syslog_pol -priority 100 (older-style policies: bind system global <policy> <priority>). GUI: Configuration > System > Auditing > Syslog (Servers, Policies, Advanced Policy Global Bindings). UDP (default), TCP or HTTP; no TLS. BSD style by default, RFC 5424 with -syslogCompliance RFC5424. Only one action per server address and port. Yes, after a setting on the device dataSource is <NetScaler address as the Collector sees it>; text -PPE- (vendor samples) or CEF:0|Citrix|NetScaler (Web App Firewall in CEF mode) High
VMware vCenter Server Admin logins, virtual machine and permission changes; a ransomware target Appliance management page https://<vcsa>:5480 > Syslog > Forwarding Configuration > Configure: server, protocol (TLS, TCP, RELP or UDP; leave RELP off), port 7014. Up to three destinations; "Send Test Message" button. Guide name must avoid the vmware match (section 4(c)(4)). Yes, after a setting on the device dataSource is <vCenter IP>; no confirmed text High
Veeam Backup & Replication Backup jobs, deleted backups, malware found in backups, four-eyes approvals Version 12.1 and later: main menu > Options > Event Forwarding > Syslog servers > Add (server, transport TCP, UDP or TLS, port 7014). Version 13 web interface: gear icon > Event Forwarding > Syslog Servers > New. RFC 5424; over TCP and TLS each message ends with a newline by default. One syslog server only; needs a paid license. The Windows channel Veeam Backup is the worse route (not read, unnamed data; table 3b and 4(b)). Yes, after a setting on the app dataSource is <backup server IP>; text Veeam_MP High
Synology NAS (DSM 7) File access, admin logins and deletions on the NAS; a ransomware target Log Center > Log Sending > "Send logs to a syslog server": server, port 7014, transfer protocol (UDP, TCP, or TLS with an imported certificate), log format BSD (RFC 3164) or IETF (RFC 5424). "Send test log" button. Yes, after a setting on the device dataSource is <NAS IP>; no confirmed text High
QNAP NAS (QTS, QuTS hero) File access, admin logins and deletions on the NAS; a ransomware target QuLog Center > QuLog Service > Log Sender: "Send to Syslog Server" (RFC 3164) or "Send to QuLog Center" (RFC 5424); host, port 7014, transfer protocol, log types (event logs and access logs). The protocol choices on the sender page are not confirmed. Yes, after a setting on the device dataSource is <NAS IP>; no confirmed text High
F5 BIG-IP Load balancer admin and system events; request logs GUI: System > Logs > Configuration > Remote Logging (UDP only), or tmsh modify /sys syslog remote-servers add { utm { host <collector> remote-port 7014 } }. Plain TCP only through a modify /sys syslog include "..." statement (F5 article K13080); no TLS. Request logs go through high-speed logging (System > Logs > Configuration > Log Destinations; TCP or UDP; rfc3164, rfc5424 or legacy-bigip). The Collector must be reachable from the management network or route domain 0. Yes, after a setting on the device (UDP, or TCP through the include statement) dataSource is <BIG-IP IP>; no confirmed text Medium
Juniper SRX firewalls and EX switches Firewall sessions, admin logins, configuration changes System logs: set system syslog host <collector> any any, set system syslog host <collector> port 7014, set system syslog host <collector> transport tcp (the transport statement exists from Junos 21.2R1 on EX and 21.3R1 on SRX). SRX traffic and security logs in stream mode: set security log mode stream, set security log stream utm host <collector>, set security log stream utm port 7014, set security log stream utm format sd-syslog, set security log stream utm transport protocol tcp. Yes, after a setting on the device dataSource is <device IP>; text RT_FLOW_SESSION (SRX traffic) or junos@2636 (sd-syslog format) Medium
Cisco ISE Network access logins (802.1X, VPN) and failures Administration > System > Logging > Remote Logging Targets > Add (TCP Syslog, port 7014), then Administration > System > Logging > Logging Categories: add the target to Passed Authentications, Failed Attempts and RADIUS Accounting. A message longer than "Maximum Length" (default 1024) is split into numbered segments. Guide name must avoid the cisco match (section 4(c)(4)). Partly: long messages arrive as several separate logs. Raise Maximum Length as far as the version allows (Cisco documents disagree: 1024 or 8192); over UDP keep it at 2048 or less dataSource is <ISE node IP>; text CISE_Failed_Attempts or CISE_Passed_Authentications Medium
Aruba ClearPass Policy Manager Network access logins and failures Administration > External Servers > Syslog Targets (host, protocol TCP, port 7014), then Administration > External Servers > Syslog Export Filters (export template, event format CEF, LEEF, RFC 5424 or standard, target). Yes, after a setting on the device dataSource is <ClearPass IP>; text ClearPass (CEF and LEEF) Medium
Barracuda CloudGen Firewall Firewall and VPN events Configuration Tree > Box > Infrastructure Services > Syslog Streaming: enable, then Logdata Filters, Logstream Destinations (IP, port 7014, TCP) and Logdata Streams. Yes, after a setting on the device dataSource is <firewall IP>; no confirmed text Medium
Zyxel ATP and USG FLEX Firewall events at small offices ZLD firmware: Configuration > Log & Report > Log Settings > Remote Server 1 to 4 > Edit (Active, Log Format, Server Address, Server Port 7014). USG FLEX H (uOS): Log & Report > Log Settings > Remote Syslog Server (CEF or Syslog; the port field is confirmed only by a Zyxel Community answer). Transport not confirmed. Yes, after a setting on the device dataSource is <firewall IP>; no confirmed text Medium
OPNsense Firewall events System > Settings > Logging, "Remote" tab: add a destination (Transport TCP or TLS, Hostname, Port 7014, optional RFC5424). Yes, after a setting on the device dataSource is <firewall IP>; no confirmed text Medium
SonicWall SMA 1000 and SMA 100 Remote access logins SMA 1000 (12.4): Monitoring > Logging > Configure Logging > Syslog (port, TCP, UDP or TLS). SMA 100 (10.2): Log > Settings > Syslog Settings (port and transport not confirmed). Guide name must avoid the sonic match (section 4(c)(4)). Yes, after a setting on the device (SMA 100 port not confirmed) dataSource is <appliance IP>; no confirmed text Medium
Email security gateways (Cisco Secure Email, Barracuda Email Security Gateway, FortiMail) Phishing and malware in mail; admin logins Cisco Secure Email (AsyncOS 16.5): System Administration > Log Subscriptions > Add Log Subscription, retrieval method "Syslog Push" (host, port 7014, UDP, TCP or TLS; set "Maximum message size" to 2048 or less on UDP and 8192 or less on TCP); log types include mail logs, authentication logs and Consolidated Event Logs (CEF). Barracuda Email Security Gateway: ADVANCED > Advanced Networking (mail syslog address, port, TCP recommended). FortiMail 7.6: Log & Report > Log Setting > Remote > New (port 7014; "TCP (legacy)" uses newline framing; long logs are split into parts). Guide names must avoid the cisco and fortinet matches (section 4(c)(4)). Yes, after a setting on the device dataSource is <gateway IP>; text CEF:0|Cisco| (Cisco Consolidated Event Logs) or log_id= (FortiMail) Medium
NetApp ONTAP Admin commands on storage: who changed what cluster log-forwarding create -destination <collector> -port 7014 -protocol tcp-unencrypted -message-format rfc-5424 (System Manager 9.11.1 and later: Events & Jobs > Audit Logs > Manage Audit Destinations). Forwards the audit log: change commands by default, read commands only if turned on. System events use a separate setting: event notification destination create -syslog <collector> -syslog-port 7014. Yes, after a setting on the device dataSource is <cluster address as the Collector sees it>; no confirmed text Medium
Server management controllers (Dell iDRAC9, HPE iLO 6) Out-of-band admin logins and hardware events iDRAC9: Configuration > System Settings > Alert Configuration > Remote Syslog > Settings, or racadm set iDRAC.SysLog.Server1 <collector> and racadm set iDRAC.SysLog.Port 7014. Basic mode is UDP only; Secure mode is TLS over TCP (firmware 6.00.02.00 and later). HPE iLO 6: Management > Remote Syslog > Add (UDP or TLS, port 7014, RFC 5424; needs a license). Neither offers plain TCP. Yes, after a setting on the device (UDP, or TLS once the Collector has a certificate) dataSource is <iDRAC or iLO IP>; no confirmed text Medium
Infoblox NIOS DNS queries, DHCP leases, admin changes Grid > Grid Manager > Members > Grid Properties > Edit > Monitoring > Log to External Syslog Servers > Add (address, transport UDP, TCP or Secure TCP, port 7014, severity, categories); "Copy Audit Log Messages to Syslog" adds admin changes. DNS query logging: Data Management > DNS > Grid DNS Properties > Logging (Infoblox warns it slows DNS). Yes, after a setting on the device dataSource is <Grid member IP>; no confirmed text Medium
Linux, BSD and Unix hosts without the agent Hosts where the agent cannot be installed rsyslog, in /etc/rsyslog.d/90-utmstack.conf: action(type="omfwd" target="<collector>" port="7014" protocol="tcp" queue.type="linkedList"), then restart rsyslog. Framing is newline by default; TCP_Framing="octet-counted" also works with the Collector. Yes, after a setting on the host dataSource is <host IP>; no confirmed text Medium
APC UPS (Network Management Card 2 and 3) Power events and card logins Configuration > Logs > Syslog > Servers (server, port 7014, protocol; up to four servers). Card 2: UDP or TCP; card 3: UDP, TCP or TLS. Syslog must also be chosen as the notice method for each event. The tag is the event type (APC:, System:, Device:). Yes, after a setting on the device dataSource is <card IP>; no single confirmed text Low
Fortinet FortiAuthenticator and FortiNAC Authentication and network access events FortiAuthenticator 6.6: Logging > Log Config > Syslog Servers > Create New (port, level, facility, optional secure connection), then enable "Send system logs to remote Syslog servers". FortiNAC: System > Settings > System Communication > Log Receivers > Add (port; Syslog CSV or Syslog CEF). Guide name must avoid the fortinet match (section 4(c)(4)). Yes, after a setting on the device dataSource is <appliance IP>; text NAC Control Server (FortiNAC CEF) Low

Left out on purpose, to keep the table at 25 rows: Stormshield SNS (Configuration > Notifications > Logs - Syslog - IPFIX > SYSLOG tab; UDP, TCP or TLS; its LEGACY-LONG format over UDP can pass 2 KB), Nutanix (Prism Central: Admin Center > Settings > Alerts and Notifications > Syslog Server; UDP or TCP; one server only), Progress Kemp LoadMaster (System Configuration > Logging Options > Syslog Options), TrueNAS (System > Advanced Settings > Syslog, host:port) and Eaton Network-M2 and M3 cards (Settings > Protocols > Syslog). All five can send to port 7014; they are lower priority for mid-market customers. Also left out: Sophos UTM 9 (end of life on 30 June 2026), TP-Link Omada and Ruckus controllers (settings found, but transport and format not confirmed), and cloud-only services (no syslog output from a device).

Sources checked for this list (24 Sep 2026)

Sources for 3a (vendor documentation, checked 2026-09-24):

  • Check Point: Log Exporter Administration Guide (sc1.checkpoint.com/documents/Log_Exporter/EN/CP_Log_Exporter_AdminGuide.pdf, dated 7 September 2026); Quantum Spark R82.00.X Locally Managed Administration Guide, "Configuring External Log Servers"; CheckMates "Log-Exporter guide" (community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-guide/td-p/9035) for the CheckPoint sample.
  • WatchGuard: watchguard.com/help/docs/help-center/en-US/Content/en-US/Fireware/logging/send_logs_to_syslog_c.html; .../WG-Cloud/Devices/managed/configure_log_servers.html.
  • Ubiquiti: help.ui.com/hc/en-us/articles/33349041044119 (UniFi System Logs and SIEM Integration, updated 19 August 2026); help.uisp.com/hc/en-us/articles/22591220015511 (EdgeRouter remote syslog).
  • HPE Aruba: arubanetworking.hpe.com/techdocs AOS-CX CLI Bank (logging), AOS-S 16.11 "Using TCP" and 16.10 "TLS", Instant syslog-server, AOS 8 logging.
  • Ivanti: help.ivanti.com/ps/help/en_US/ICS/22.x/ag/logging_n_monitoring.htm.
  • Juniper: juniper.net Junos documentation "syslog over TLS", system syslog host transport, "System Logging for a Security Device", security log stream.
  • Cisco ISE: ISE 3.4 Administrator Guide, "Basic Setup"; Cisco technote 222223 "Configure External Syslog Server on ISE"; "Cisco ISE Syslogs" reference.
  • Aruba ClearPass 6.12 User Guide: "Syslog Targets", "Syslog Export Filters".
  • Barracuda: campus.barracuda.com/product/cloudgenfirewall/doc/79463292/how-to-configure-syslog-streaming/.
  • Zyxel: mysupport.zyxel.com/hc/en-us/articles/360009952439 (ZLD), .../30479809338258 (USG FLEX H), community.zyxel.com/en/discussion/27525.
  • OPNsense: docs.opnsense.org/manual/settingsmenu.html and the Syslog.xml model in github.com/opnsense/core.
  • SonicWall: SMA 1000 12.4 Administration Guide "Sending log files to a syslog server"; SMA 100 10.2 Administration Guide "Syslog settings".
  • rsyslog: docs.rsyslog.com/doc/configuration/modules/omfwd.html.
  • Stormshield: documentation.stormshield.eu/SNS/v4/en/Content/User_Configuration_Manual_SNS_v4/Logs-syslog/Syslog_tab.htm.
  • Fortinet: docs.fortinet.com FortiAuthenticator 6.6.0 "Log configuration"; FortiNAC 9.2.0 "Log receivers" and 9.4.0 "Log events to an external log host".
  • Sophos UTM end of life: community.sophos.com "Sophos UTM/SG End of Life Frequently Asked Questions".
  • NetScaler: docs.netscaler.com/en-us/citrix-adc/current-release/system/audit-logging/configuring-audit-logging.html; developer-docs.netscaler.com audit-syslogAction command reference; .../application-firewall/logs.html.
  • VMware vCenter: techdocs.broadcom.com vSphere 8.0 "Forward vCenter Server Log Files"; knowledge.broadcom.com article 431046.
  • Veeam: helpcenter.veeam.com/docs/vbr/userguide/syslog_servers_add.html; veeam.com/kb4522; helpcenter.veeam.com/docs/vbr/events/event_40100.html (sample with Veeam_MP).
  • Synology: kb.synology.com/en-global/DSM/help/LogCenter/logcenter_client?version=7.
  • QNAP: docs.qnap.com/operating-system/qts/5.2.x/en-us/configuring-log-sender-settings-66DE0C94.html; qnap.com FAQ "What kind of syslog format can QNAP NAS receive and send".
  • F5: my.f5.com/manage/s/article/K13080; clouddocs.f5.com tmsh reference sys log-config destination remote-syslog and ltm profile request-log.
  • Cisco Secure Email: Cisco Secure Email Gateway AsyncOS 16.5 User Guide, "Logging".
  • Barracuda Email Security Gateway: campus.barracuda.com/product/emailsecuritygateway/doc/12193950/syslog-and-the-barracuda-email-security-gateway/.
  • FortiMail: docs.fortinet.com FortiMail 7.6.3 Administration Guide "Configuring logging"; 7.4.0 Log Reference "Log message syntax".
  • NetApp: docs.netapp.com/us-en/ontap-cli/cluster-log-forwarding-create.html; docs.netapp.com/us-en/ontap/system-admin/forward-command-history-log-file-destination-task.html.
  • Dell iDRAC9: dell.com iDRAC9 7.xx User's Guide "Configuring remote system logging"; iDRAC9 Security Configuration Guide "Remote syslog with TLS"; RACADM guide iDRAC.SysLog.Port. HPE iLO 6: support.hpe.com iLO 6 User Guide, "Remote Syslog".
  • Infoblox: docs.infoblox.com/space/nios90/1380844672/Specifying+Syslog+Servers.
  • APC: Schneider Electric Network Management Card 2 User Guide 990-3402R and Card 3 User Guide 990-91148R (se.com).
  • Left-out products: Stormshield SNS v4 manual "Syslog tab"; portal.nutanix.com Prism Central Admin Center Guide "Syslog server"; docs.progress.com LoadMaster "Syslog Options"; truenas.com SCALE "Managing syslogs"; Eaton Network-M2 and M3 user guides.

Done per technology

  • A guide-only entry with a real display name, a one-line description (all seven languages) and an icon.
  • A guide built from the shared template, with the vendor steps from the table, the exact setting, and how to check the logs arrived.
  • A "View logs" link that opens the Log Explorer with the filter from the table.
  • Checked once with the real product, or with a realistic sample sent the same way, and the logs show up under that filter.
  • Where the table says "Partly" or "No", the guide says plainly what the customer does not get yet.

Research notes this list relies on

0.1 The generic syslog port is 7014, not 514

  • The listener lives in the UTMStack Collector (the utmstack_forwarder service in collectors/forwarder). collectors/forwarder/config/const.go sets ProtoPorts[syslog] = {UDP: "7014", TCP: "7014"}. The forwarder README table and protoCatalog.ts say the same. TCP on 7014 can be switched to TLS (encrypted TCP) with enable-integration syslog tls or the remote-enable panel.
  • Nothing in agent, log-input, shared or installer listens for syslog. The v12 agent has no syslog listener at all. The v11 agent had one (agent/collector/syslog on branch v11), and its generic syslog port was also 7014 (agent/config/const.go on v11).
  • The "514/udp" in collectors/syslog.tsx, the default of CollectorEndpointInfo and GenericCollectorGuide is wrong for generic syslog. In the Collector, UDP 514 and TCP 1470 are the default ports of the four Cisco data types (firewall-cisco-asa, firewall-cisco-firepower, cisco-switch, firewall-meraki).
  • The UTMStack server itself publishes no syslog port (installer/docker/compose.go publishes only the web front end). Port 7014 is open only on a Linux host where the Collector is installed and syslog has been enabled on it.

So every syslog guide must say: install the Collector (or reuse one), enable data type syslog, then point the device at <collector host>:7014.

0.2 Collector limits that change what a guide should recommend

From collectors/forwarder/collector/syslog/ (listener.go, framing.go, handler.go):

  • UDP: the read buffer is 2048 bytes. A longer datagram is cut at 2048 bytes without any error. Verbose devices (web firewalls, remote-access gateways, anything sending key=value or CEF lines) should use TCP.
  • TCP: the first byte of each frame decides the framing. A digit means "octet counting" (length prefix), < means one message per line. Any other first byte is an error and the connection is closed. Octet-counted messages longer than 8192 bytes are rejected and the connection is closed. In practice the device must send a normal syslog header that starts with <priority>.
  • One UDP datagram is stored as one log, even if it contains several lines.
  • The sender identity stored with each log (dataSource) is the sender's IP address as the Collector sees it (a sender on 127.0.0.1 is replaced by the Collector's host name). If devices relay through another syslog server, every log shows the relay's IP address.

0.3 What the generic syslog parser keeps

definitions/filters/syslog/syslog-generic.yaml has one grok step that copies the whole line into log.message. There is no host name, program, facility or severity field. The only way to tell devices apart is dataSource (the sender IP address) or free-text search on the raw line.

4(a) The generic syslog parser keeps only the whole line

Today syslog-generic.yaml copies the raw line into log.message and nothing else, so a guide can only say "filter on dataSource = the device's IP address". The smallest useful change is to parse the standard syslog header, and nothing inside the message. Use the same field names the Linux filter already uses for journald, so one Log Explorer filter works on both channels:

Field From RFC 5424 header From RFC 3164 (BSD) header
log.priority <PRI> number <PRI> number
log.syslogTimestamp TIMESTAMP (text as sent) Mmm dd hh:mm:ss (text as sent)
origin.host HOSTNAME HOSTNAME
log.syslogIdentifier APP-NAME TAG (text before [ or :)
log.syslogPid PROCID the number in [...] after the tag
log.messageId MSGID (none)
log.message the text after the header (the whole line stays in raw) the text after tag[pid]:
severity (optional) label from priority mod 8, same labels as linux.yaml (emergency ... debug) same

Rules for the change:

  1. Keep today's step first, so log.message always exists even when no header matches.
  2. Add one grok step per header shape, each guarded by a where on raw (for example regexMatch("raw", "^<[0-9]{1,3}>1 ") for RFC 5424), and only then overwrite log.message with the part after the header.
  3. Lines without a host name (common: <PRI>Mmm dd hh:mm:ss tag: text) and lines that are not syslog at all (CEF, key=value without a header) must fall through untouched. Test with real samples in the pipeline playground before shipping; the grok patterns can reuse the built-in names in backend/modules/eventprocessing/repository/engine_config.go ({{.integer}}, {{.monthName}}, {{.monthDay}}, {{.time}}, {{.hostname}}, {{.notSpace}}, {{.greedy}}).
  4. Severity needs arithmetic the filter language does not have; eight add steps with oneOf("log.priority", [...]) lists (the 24 values for each severity) do the same job, like the priority mapping in linux.yaml.

With this in place a device guide can give log.syslogIdentifier or origin.host filters that survive IP address changes and relays.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions