To set up the Edge Filer Syslog service:
-
In the global administration view, select Services > Edge Filer Syslog in the navigation pane.
The Edge Filer Syslog page is displayed.

-
Click Add a Server to define the Syslog Server:
The New Syslog Server window is displayed.

Address – The address of the Syslog server.
Port – The syslog server's port number. The default port used by a syslog server is 514 when Protocol Type isUDPand 6514 when Protocol Type isTCP/TLS
Protocol – The protocol to use for sending logs to the syslog server:UDPorTCP/TLS
IfTCP/TLSis chosen the New Syslog Server window changes:

- Click Client Certificate to upload the client certificate.

- Click Select File to select the .pem file client certificate to use.
Note
Only pem files are allowed.
- Click Select File to select the private key. The private key must match the certificate.
- Click Server Certificate to upload the server certificate.

- Click Select File to select the .pem file server certificate to use.
Note
Only pem files are allowed. The certificate must match the client certificate.
- Click Save.
If there is a problem with the TCP connection or with the TLS certificate, for example the client and server certificates do not match or a certificate has expired, an error is displayed, with additional information written to the system log.
Alert if lag exceeds – The number of messages that are not sent to the Syslog server before an alert is issued,
- Click Client Certificate to upload the client certificate.
-
Click Save.
The server is added to the list of servers.

The Status field isUnknownif the UDP protocol is used and eitherConnectedorNot Connectedif the TCP protocol is used.NoteTo delete a server, select the server row and click Delete and in the confirmation window click Delete.
-
Click Enable in the status bar.
The Edge Filer Syslog service starts.

When the service has finished starting the status changes to Active and Running OK.

-
Enable CIFS/SMB Audit Logs on every CTERA Edge Filer you want to use with the Edge Filer Syslog service and enable log forwarding to the portal on these edge filers. Log forwarding is enabled from edge filer version 7.11.x in the user interface, in the Logs > Log Forwarding page and in earlier versions using CLI.