Skip to content

Commit

Permalink
Merge pull request #2080 from SEKOIA-IO/add_info_firebox
Browse files Browse the repository at this point in the history
add warning to not have timestamp issues
  • Loading branch information
pbivic authored Nov 7, 2024
2 parents 63861e7 + 420dc53 commit 25414ab
Showing 1 changed file with 3 additions and 0 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,9 @@ An internal log concentrator (Rsyslog) is required to collect and forward events

Log on your Firebox appliance and follow [this guide](https://www.watchguard.com/help/docs/help-center/en-US/Content/Integration-Guides/General/ubuntu_rsyslog.html) to enable syslog forwarding.

!!! warning
Make sure that you didn't check the "time stamp" box in your Syslog Server configuration.

Configure the event forwarding to use the IBM LEEF format (for more information, please read the [associated documentation](http://www.watchguard.com/help/docs/fireware/12/en-us/Content/en-US/logging/send_logs_to_syslog_c.html)).

## Create the intake
Expand Down

0 comments on commit 25414ab

Please sign in to comment.