Create a syslog alert response

Create a syslog alert response to connect to an external syslog server. This enables you to send event alerts to an external syslog server with customizable severity and facility settings.

Before you begin

  • This procedure is not the recommended way to send syslog messages in many cases. For more information, see

  • Confirm that your syslog server can accept remote messages.

Procedure


Step 1

Choose Administration > Alerts.

Step 2

From the Create Alert drop-down menu, choose Create Syslog Alert.

Step 3

Enter a Name that you want to use for the alert.

Step 4

In the Host field, enter the hostname or IP address of your syslog server.

Note

If you enter an invalid IPv4 address (such as 192.168.1.456), Firewall Management Center treats it as a hostname and does not display a warning.

Step 5

In the Port field, enter the port the server uses for syslog messages. By default, this value is 514.

Step 6

From the Facility list, choose a facility. For more information, see Syslog alert facilities.

Step 7

From the Severity list, choose a severity. For more information, see Syslog severity levels.

Step 8

In the Tag field, enter the tag name that you want to appear with the syslog message.

For example, if you wanted all messages sent to the syslog to be preceded with FromMC, enter FromMC in the field.

Step 9

Click Save.


What to do next

  • If you are using syslog alert responses to send connection logs to a syslog server, you must deploy configuration changes after you modify the syslog alert responses.