7 Configuring event processing rules : 7.5 Collecting and processing Syslogs
NOTE: For Syslog message processing, ALL Syslog sources (e.g. workstations, servers, network appliances, etc.) must be configured to send their messages to the computer/IP where GFI EventsManager is installed. This applies also for the computer that is running GFI EventsManager.
2. Click on the Syslog tab.
IMPORTANT: Deleting events from source logs without having them archived or backed-up may lead to legal compliance issues. Please make sure to archive or backup important events according to the standards implied by data retention and data protection regulations.
NOTE 1: The GFI EventsManager Syslog server is by default configured to listen for Syslog messages on port 514. For more information on how to customize Syslog server port settings refer to the ‘Configuring Syslog server communications port’ section in this chapter.
NOTE 2: The built-in Syslog server will only accept Syslog messages sent from the computers that are part of this computer group.