Go to Settings >> Configuration from the navigation bar and click Normalization Policies.
Click Add.
Enter a Policy Name.
Select ESETCompiledNormalizer.
Click Submit.
Selecting a Normalization Package¶
Go to Settings >> Configuration from the navigation bar and click Devices.
Click Add.
Enter a device Name.
Enter the IP address(es) of the ESET server.
Select the Device Groups.
Select an appropriate Log Collection Policy for the logs.
Select a collector or a forwarder from the Distributed Collector drop-down menu.
Note
It is optional to select the Device Groups, the Log Collection Policy and the Distributed Collector.
Select a Time Zone.
Note
The timezone of the device must be the same as its log source.
Configure the Risk Values for Confidentiality, Integrity and Availability used to calculate the risk levels of the alerts generated from the device.
Click Submit.
Adding ESET as a Device¶
Go to Settings >> Configuration from the navigation bar and click Devices.
Search for the previously added device.
Click the Add icon from Actions.
Click Syslog Collector.
Available Collectors and Fetchers¶
Select Syslog Parser as Parser.
Select a Processing Policy that uses the previously created normalization policy.
Select the Charset.
Select None in Proxy Server.
Click Submit.
Configuring Syslog Collector¶
We are glad this guide helped.
Please don't include any personal information in your comment
Contact Support