Forum Discussion

zposz365's avatar
zposz365
Copper Contributor
Jun 16, 2021

Configure syslog from two different sources

Hello,

 

I currently have CheckPoint Firewall logs coming to my Azure Linux server in CEF format and those are getting sent to Sentinel without issue. I am currently trying to get Cisco Meraki syslog to send to Azure Sentinel as well using the same server. Can I send both of these logs to port 514 on my Azure server running the oms agent? If so can someone help me get these logs flowing to Sentinel. If not can someone please guide me on the configuration files I would need to update? Thanks.

1 Reply

  • PrashTechTalk's avatar
    PrashTechTalk
    Brass Contributor
    Both logs can be sent on poet 514. Did you go to though the Azure Sentinel built-in connector for Cisco Meraki which is still in preview and its documentation?
    though this is for reporting the link below should get some info on your port related question.
    https://documentation.meraki.com/General_Administration/Monitoring_and_Reporting/Meraki_Device_Reporting_-_Syslog%2C_SNMP%2C_and_API

Resources