Enable forwarding of Cyber Vision events and alerts to an external syslog server to integrate with a Security Information and Event Management (SIEM) system.
To configure syslog, follow these steps:
Before you begin
-
Ensure you have administrator access to Cyber Vision Center.
-
Confirm that the external syslog server is accessible. Obtain the host IP address, port, and the required protocol.
-
If secure communication is required, ensure you have the P12 certificate from your SIEM administrator.
-
Recent syslog format changes:
-
Standard and RFC3164 formats are deprecated.
-
Standard/CEF is now named CEF.
-
RFC3164/CEF is now named CEF Extended Time Precision.
Note
If the deployment had Standard or RFC3164 formats configured, version 5.3.x setup migrates the configuration to CEF.
Procedure
-
From the main menu, choose Admin > System.
-
Click Configure in the Syslog configuration menu.
-
Select Protocol.
Note
If secure communication is required, select TCP + TLS and import the P12 certificate.
-
Enter the syslog server Host IP address and Port that are accessible from Cyber Vision Center.
-
Select the required Format.
-
CEF: This format, based on the Common Event Format (CEF) standard, sends events with second-precision timestamps.
-
CEF Extended Time Precision: This format, based on the Common Event Format (CEF) and an extended syslog header, sends events with millisecond-precision timestamps.
-
Save the configuration.
Cyber Vision Center sends events from the Classic UI to syslog with 'Version Number = 1.0.' It sends alerts from the New UI to syslog with 'Version Number = 2.0.
What to do next
To configure notifications for specific alert types, see "Enable or disable syslog notifications for alert types" in the Cisco Cyber Vision New UI Administrator Guide.
To export events using syslog, see "Configure event export to syslog (Classic UI)" in the Cisco Cyber Vision Syslog Notification Format Configuration Guide.