cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Jaeseok
Level 7
Report Inappropriate Content
Message 1 of 6

ePO syslog question

Hi,

 

I want to link ePO to another syslog server. By the way, I know that ePO only supports tls1.2. Is there a way for ePO to connect in a clear text way rather than a TLS1.2 way?

Because of this I'm failing to integrate between a regular syslog server or spunk and ePO.

 

Thanks. 

5 Replies
cdinet
Employee
Employee
Report Inappropriate Content
Message 2 of 6

Re: ePO syslog question

No, epo will only connect via ssl using tls 1.2.  KB91194 lists ciphers that epo can use with syslog.  

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

Jaeseok
Level 7
Report Inappropriate Content
Message 3 of 6

Re: ePO syslog question

ok. thanks

 

I registered syslog server with TLS 1.2.  in "ePO > Configuration > Registred servers".

and I clicked [Test Connection] button. so the result is "Syslog connection sucess".

 

but, After that, despite the occurrence of a firewall threat event in ENS on any endpoint, ePO does not forward the event message to syslog.
What should I do in addition?

Thanks. 

cdinet
Employee
Employee
Report Inappropriate Content
Message 4 of 6

Re: ePO syslog question

What does the eventparser log show for any errors?  You can also run a wireshark when starting up eventparser service to see what is happening with the handshake.  

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

Ufoto
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 5 of 6

Re: ePO syslog question

Hello,

Apologies for jumping in this thread, but I believe my question will also help the author. When are the events forwarded to Syslog exactly? Are they sent to Syslog by the event parser as soon as they are received (constant flow of events), or are they cached and then sent in bulk? 

I am asking because upon checking the Audit Log I can see only few "Forward events" entries per day, while there are hundreds of systems connected to the respective ePO / Agent handlers. 

 

Was my reply helpful?
If you find this post useful, Please give it a Kudos! Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!
cdinet
Employee
Employee
Report Inappropriate Content
Message 6 of 6

Re: ePO syslog question

Events are forwarded as soon as they hit the eventparser folder and processed by eventparser, never cached and sent in bulk.  Those would also not be logged in the audit log, or there would be nothing but that in the log.  You may see that if you have an automatic response that sends events to an snmp server or something like that - I would have to see what the event was to know for sure.  You can match that with server task log also to see what was running.

Otherwise you have to look at the eventparser log to see what the errors are.  If you see ssl handshake errors, then you would first probably want to get an nmap output from the syslog server on their ssl port.

KB91194 - syslog tls requirements

kb91115 - how to run nmap

If all else fails, stop eventparser, start up wireshark on epo server, start up eventparser.  When you see failures in the log, check wireshark for the client hello, server hello response.  If there is no server hello response, then syslog isn't set up to use tls or they are using wrong port.

Additionally, if the syslog server requires mutual authentication, such as a cert returned from epo, that will fail - we don't support mutual authentication with syslog.

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from product experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by employees.
Join the Community
Join the Community