Skip to main content
Version: NG-2.13

Syslog

Introduction

Syslog O11ysource is a component that collects logs from different parts of the system

Getting Started

Compatibility

The Syslog O11ySource is compatible with all system logs and network device logs.

Data Collection Method

vuSmartMaps collects system data and network device data for Syslog O11ySource using an internal agent. The agent gathers data based on the configuration specified at the source. This data can be received from both UDP and TCP protocols, depending on the source system configuration.

Prerequisites

Inputs for Configuring Data Source

  • Host: The IP Address/FQDN of the Syslog server. This field is the key to identify each server you add here.
  • Transport Protocol: Specify the transport protocol to be used for receiving the data: TCP or UDP
  • Port: Provide the port details

Firewall Requirement

To collect data from this O11ySource, ensure the following ports are opened:

Source IPDestination IPDestination PortProtocolDirection
vuSmartMaps IPIP address of Syslog server(s)514* (UPD), 6514* (TCP)UDP/TCPOutbound

*Before providing the firewall requirements, please update the port based on the customer environment.

Configuring the Target

Users must configure their system to send Syslog data to a UDP/TCP port on their system, which will then forward the logs to the vuSmartMaps Data Collector End Point via TCP.

Configuration Steps

  • Enable the Syslog O11ySource.
  • Select the sources tab and press the + button to add a new instance that has to be monitored.
  • Provide the required configurations:
  • *Host
  • *Transport Protocol
  • *Port
  • Click Save to close the data source window.

Metrics Collected

NameDescriptionData Type
TimestampTimestamp at metricsets collectedDateTime
Facility CodeUsed to categorize log messages based on their sources or purposesUInt16
MessagenanString
ProcIDProvides the process name or process ID associated with a syslog systemString
Severity CodeCodes range from 0 to 7, with each level representing a different severityUInt8
AppNameIdentifies the name of the application or process that generated the log entry.String
FacilityUsed to specify the type or source of the log messageString
HostHost IP of incoming logString
HostNameHost Name of incoming logString
Log SeverityIndicates the seriousness or urgency of a log messageLowCardinality(String)
Message LowernanString
Log UUIDnanUUID
Network TypenanString