Jan 22 2019
09:36 PM
- last edited on
Nov 30 2021
10:06 AM
by
TechCommunityAP
Jan 22 2019
09:36 PM
- last edited on
Nov 30 2021
10:06 AM
by
TechCommunityAP
We have configured all the settings to forward events through Syslog through port 514 and network access is also verified. But the events are not forwarding to arcsight SIEM.
Jan 23 2019 05:37 AM
Are there any errors in the center logs that seems related?
I am guessing you are using UDP. if your SIEM supports it I would suggest for troubleshooting switching to TCP. in UDP, if there is a network blocker, We can't tell. for TCP we will generate errors in the logs.
Jan 27 2019 10:41 PM
Have you tested the connection with Arcsight? If yes, did Arcsight receive the test message?
There is a test button on the page you configure the settings to send the notifications to your SIEM.