Security Compliance
Syslog events are not appearing in the SEM Console
This SEM article describes what to do if events sent from a syslog device are not appearing in the SEM Console.
First published date
Last published date
Overview
This Security Event Manager (formerly Log & Event Manager) article describes what to do if events sent from a syslog device are not appearing in the SEM Console.
Product section
Cause
Resolution
- Perform an Historical Events & Reports search for all events coming from that connector.
- Go to SEM Gui > Historical Events.
- Refine Results > Event Groups and drag the Any Alert.ToolAlias field to the search bar. ("Any Alert".ToolAlias = "*")
- Type the name of your connector after the equal sign. You can also use a partial name and surround it with asterisks (*) as wildcards. Example: ("Any Alert".ToolAlias = "*Aruba*")
- Specify a search time frame from the dropdown and click the Search button. If you get no results or only InternalToolOnline/InternalToolOffline events, there might be a configuration issue.
- Verify that the connector you have configured for your syslog device is looking in the log file that your device is sending its events to:
- Go to Configure > Manager connectors and find the connector you've configured. The log being monitored will be shown in the Log File field.
- Verify that the syslog events are being received in that same log file by searching the raw log file for the IP address of your device. To check the raw log files on your SEM, see Use the CMC checklogs command to display log files
- Verify that the connector you've configured is enabled and showing a green status icon.
- If everything is configured and you still see no events, your connector may be out of date and unable to parse those particular events. See Updating SEM Connectors.