Submit a ticketCall us

Don’t fall victim to a ransomware attack
Backups are helpful, but sometimes that’s not enough to protect your business against ransomware. At our live webcast we will discuss how to protect against ransomware attacks with SolarWinds® Patch Manager and how to leverage log data to detect ransomware. Register now for our live webcast.

Home > Success Center > Log & Event Manager (LEM) > Set up Officescan syslog messages with LEM

Set up Officescan syslog messages with LEM

Table of contents
Created by Ezgi Muderrisoglu, last modified by MindTouch on Jun 23, 2016

Views: 119 Votes: 0 Revisions: 4


This article provides information on how to set up Officescan application sending syslog to LEM.


  • LEM version 6.2
  • Officescan version 11


Note:The TrendMicro Officescan connector is not available in the LEM console. You can find it available in LEM console > Manage > Nodes > click on the Gear icon of the machine agent where it installed, and then click Connectors.


A. Confirm the syslog sending:

  1. Confirm that the Officescan is configured correctly to send syslogs to LEM. Contact TrendMicro support if you have any questions regarding this. If the Officescan is sending the syslogs, then LEM should pick them up, they appear when you run checklogs (cmc > appliance > checklogs > location where syslogs are being sent to (the logs are located found here).

B. Confirm the integration of the Windows server and LEM:

  1. Add the Windows server on which TrendMicro is installed, onto LEM by adding the windows server as a Node.
    This can be done by installing an agent on the Windows server.
  2. Once the Windows server is added/integrated with LEM, the server name should appear on the list of Nodes on your LEM console. 

C. Set up the Connector:

  1. Select the node with this server name. 
  2. Click on the gear icon.
  3. Click on connectors.
  4. For this node, the Officescan connector appears on the list.
  5. Once you have located the Officescan connector, configure the details accordingly with the same location where the syslogs are being sent to.

Example: If Officescan is configured to send syslog to the location (facility) to local0, then configure the officescan connector on LEM to look at the location Local0.


Last modified
20:20, 22 Jun 2016