This guide helps you in configuring Redhat Linux and EventTracker to receive the events. You will find the detailed procedures required for monitoring Redhat Linux.
...
Seceon CCE should be installed.
Allow the Syslog UDP Port 514 in the firewall/network
Configuration Steps:
The following steps describe how to configure rsyslog on Red Hat Enterprise Linux 6 or 7 to receive logs from Deep Security.
Log in as a root
Execute: vi /etc/rsyslog.conf
Uncomment the following lines near the top of the rsyslog.conf to change them from:
#$ModLoad imudp
#$UDPServerRun 514
#$ModLoad imtcp
#$InputTCPServerRun 514
to
$ModLoad imudp
$UDPServerRun 514
$ModLoad imtcp
$InputTCPServerRun 514Once done type the command
...
*.* @CCE_IP:514
...
5. Add the following two lines of text to the end of the rsyslog.conf:
#Save Deep Security Manager logs to cce.log
Local7.* /var/log/Seceon/cce.log
Depending on your manager settings, you may need to replace Local7 with another value.
6. Save the file and exit
7. Create the /var/log/Seceon/cce.log file by typing touch /var/log/Seceon/cce.log
8. Set the permissions on the CCE log so that Syslog can write to it
9. Save the file and exit
10. Restart syslog: service rsyslog restart
Verification Steps:
When Syslog is functioning, you will see logs populated in: /var/log/Seceon/cce.log
Using UI
STEP 1: Log in to UI >> SYSTEM
...
STEP 2: >> LOGS AND FLOWS COLLECTION STATUS.
...