Configuration Steps:
The following steps describe how to configure rsyslog on Red Hat Enterprise Linux 6 or 7 to receive logs from Deep Security.
Log in as a root
Execute: vi /etc/rsyslog.conf
Uncomment the following lines near the top of the rsyslog.conf to change them from:
#$ModLoad imudp
#$UDPServerRun 514
#$ModLoad imtcp
#$InputTCPServerRun 514
to
$ModLoad imudp
$UDPServerRun 514
$ModLoad imtcp
$InputTCPServerRun 514Add the following two lines of text to the end of the rsyslog.conf:
#Save Deep Security Manager logs to cce.log
Local7.* /var/log/Seceon/cce.log
Depending on your manager settings, you may need to replace Local7 with another value.
Save the file and exit
Create the /var/log/Seceon/cce.log file by typing touch /var/log/Seceon/cce.log
Set the permissions on the CCE log so that Syslog can write to it
Save the file and exit
Restart syslog: service rsyslog restart
Verification Steps:
When Syslog is functioning, you will see logs populated in: /var/log/Seceon/cce.log