Symantec Privileged Access Management

 View Only
  • 1.  About SysLog Message Data Formats and other Syslog configurations.

    Posted Oct 06, 2020 10:11 AM
    I'm working on a project in which we are implementing CA PAM 3.3.1 and integrating with ArcSite for SysLog purposes.

    The syslog admin has raised the following question: "We are getting data in CSV format which is not supported by the SIEM solution (ArcSight). Log format should be in CEF. Can you change the log format to CEF from CSV?"

    Also, regarding the syslog server configuration, when multiple syslog servers are specified with a delimiting '|' is the second syslog server a backup/failover reference or is data duplicated to both nodes concurrently?

    thanks in advance.



    ------------------------------
    Services Architect
    HCL Technologies Ltd
    ------------------------------


  • 2.  RE: About SysLog Message Data Formats and other Syslog configurations.

    Broadcom Employee
    Posted Oct 16, 2020 07:11 AM
    Sebastiano

    There is no method to modify the syslog format that we send. As for the two syslog config. That should send the same data to both concurrently.... it is not backup/failover.

    Joe Lutz


  • 3.  RE: About SysLog Message Data Formats and other Syslog configurations.

    Posted Oct 16, 2020 09:01 AM
    Thank you Joseph.

    Any recommendations for the client on how to manage the CSV formatted events in ArcSite?

    I'm wondering if other client's have raised the same issue/request in the past and whether a feasible work-around exists.

    I don't want to go back to the client empty handed and tell them we wont be able to integrate with their SIEM solution because of the hard-coded syslog format.

    ------------------------------
    Services Architect
    HCL Technologies Ltd
    ------------------------------



  • 4.  RE: About SysLog Message Data Formats and other Syslog configurations.

    Broadcom Employee
    Posted Oct 16, 2020 10:13 AM
    Sebastiano

    I know we have some clients using because we have discussed the Arcsite product in passing . I do not see any documentation on how to configure this in Arcsite but sending our syslog to a syslog forwarder may help reformat the data. I cannot believe that Arcsite cannot handle Linux style syslog messages where they can digest and create  the key pairs..... May need a forwarder for them as well... 

    Joe


  • 5.  RE: About SysLog Message Data Formats and other Syslog configurations.

    Posted Oct 16, 2020 10:29 AM
    ok, thank you Joseph for the feedback.

    ------------------------------
    Services Architect
    HCL Technologies Ltd
    ------------------------------