Security Compliance
How to set syslog local facility in HP 5130 switches for SEM
This article describes how to set syslog local facility in HP 5130 switches for SEM.
First published date
Last published date
Overview
Product section
Resolution
As stated in the following Manual: HP 5130 EI Switch Series (© Copyright 2018 Hewlett Packard Enterprise Development LP, available at https://support.hpe.com/hpesc, obtained on Dec 27, 2018) on page 58 (when searching in the PDF it's page 67 of 319) under the table Outputting logs to a log host.
Step 7 explains the full command:
The command: info-center loghost <loghost-ip-addrees> facility local7
[A different local facility number can most likely be chosen. In this example local7 was used]
Verify Logs coming to SEM
- Once this is set, log in to SEM via CMC.
- Go to appliance > checklogs > select the facility sequence number corresponding to the local you choose above. Search: /ip-address-of-switch.
- The logs should start to appear in this location. For example, local7.
- Log in to the SEM Flash console, navigate to Manage > Appliances > Connectors (by selecting the gear icon next to the appliance).
- Look for the HP Firewall connector and configure the correct log file path. For example, /var/log/local7.
- Save and start the connector, you should see the events in SEM monitor tab.
Refer to Unmatched data troubleshooting guide if you do see some unmatched data.
Configure the connector in the SEM HTML5 console (versions 6.6 and newer).
- In the SEM Events Console, navigate to Nodes > Manager Connectors.
- In the search box, enter HP Firewall.
- Select the HP Firewall connector, and then click Add Connector.
- Ensure the log file path is correct (for example, /var/log/local7), and then click Add.
- Under Configured connectors, select the connector, and then click Start.
Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment. You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.