ESET Online Help

Search English
Select the category
Select the topic

Export logs to Syslog

ESET PROTECT is able to export certain logs/events and send them to your Syslog server. Events from the following log categories are being exported to Syslog server: Detection, Firewall, HIPS, Audit and Enterprise Inspector.  Events are generated on any managed client computer running an ESET product (for example, ESET Endpoint Security). These events can be processed by any Security Information and Event Management (SIEM) solution capable of importing events from a Syslog server. Events are written to the Syslog server by ESET PROTECT.

1.To enable Syslog server, click More > Server Settings > Advanced Settings > Syslog server > Use Syslog server.

2.To enable exporting, click More > Server Settings > Advanced Settings > Logging > Export logs to Syslog.

3.Choose one of the following formats for event messages:

a.JSON (JavaScript Object Notation)

b.LEEF (Log Event Extended Format) - format used by IBM's application QRadar.

To filter the event logs sent to Syslog, create a log category notification with a defined filter.