Page 1 of 1

Syslog Support in GA Services

Posted: Fri May 23, 2014 2:10 pm
by gasmle
Hi,

due to compliance reasons our company has to log all security relevant events in central SIEM systems.
After configuring the LogManager Settings in goanywhere services (currently 3.4.2) it seems that only the "Remarks" column gets sent over the Syslog connection.
Pattern: Date GAServerName Identifier RemarksColumn
This is not sufficient for us - only the "Remarks" column doesn't bring up any context for correlation and log analysis.

Which settings we have to configure to also get the Remote IP Adresses, Usernames, Ports, Physical Pathes, and FileSizes in the Syslog Messages?

Thanks In advance
mle

Re: Syslog Support in GA Services

Posted: Wed Mar 02, 2016 12:04 pm
by EdWyche
I am using version 5.1.3 and I would like the same information to go to our SIEMS. What settings need to be made in GoAnywhere Services to make this happen.

Thank you,
Ed

Re: Syslog Support in GA Services

Posted: Tue May 17, 2016 9:15 pm
by jstanley
Same thing here. I enabled syslog and have a bout load of "restricted IP Address" messages being logged, but it doesn't give the IP.

@Linoma - any ideas on how to get usable info in the syslog message?

Re: Syslog Support in GA Services

Posted: Wed Sep 21, 2016 9:59 am
by Support_Rick
GAMFT Version 5.3 had some syslog enhancements that should address this:

> Enhanced the Syslog capabilities to support Structured Data, including the ability to specify what audit information gets sent to the Syslog server.