Syslog Connectors
If you selected Syslog Daemon during initial installation with the First Boot Wizard, the Syslog Daemon connector has already been installed.
You can add a Syslog File, Pipe, or Daemon connector in a new container. Syslog connectors for the following devices are available with ArcSight Express:
-
Cisco PIX/ASA Syslog
-
Cisco IOS Router Syslog
-
Juniper Network and Security Manager Syslog
-
Juniper JUNOS Syslog
-
UNIX OS Syslog
Be sure your device is set up to send syslog events. See your device documentation or the SmartConnector Configuration Guide for device configuration information; the guide also includes specific device mappings to ArcSight event fields as well as further information needed for configuration if you are installing the Pipe or File connectors. Mappings in the SmartConnector for UNIX OS Syslog configuration guide apply to all syslog connectors. Specific mappings per device are documented in the configuration guide for the device.
Configuration guides for these syslog connectors supported with ArcSight Express can be found on the SmartConnectors documentation site:
-
Cisco PIX/ASA Syslog
-
Cisco IOS Syslog
-
Juniper JUNOS Syslog
-
Juniper Network and Security Manager Syslog
-
UNIX OS Syslog