Go to Settings >> Configuration >> Normalization Policies.
Click Add.
Enter a Policy Name.
Select the Compiled Normalizer for Unix.
Click Submit.
Adding a Normalization Policy¶
Go to Settings >> Configuration >> Devices.
Click Add.
Creating Unix as a Device¶
Enter a device Name.
Enter the IP address(es) of the Unix server.
Select the Device Groups.
Select an appropriate Log Collection Policy for the logs.
Enter a collector or a forwarder in the Distributed Collector.
Note
It is optional to select the Device Groups, the Log Collection Policy, and the Distributed Collector.
Select a Time Zone.
Note
The timezone of the device must be the same as that of its log source.
Configure the Risk Values for Confidentiality, Integrity, and Availability used to calculate the risk levels of the alerts generated from the device.
Click Submit.
Click Syslog Collector on the Available Collectors Fetchers panel.
Available Collectors Fetchers Panel¶
Select the Syslog Parser.
Syslog Collector Panel¶
Select the Processing Policy which contains the previously added normalization policy.
Select the Charset.
Select None as Proxy Server.
Click Submit.
We are glad this guide helped.
Please don't include any personal information in your comment
Contact Support