Support external Syslog collection
planned
Nate O'Brien
Merged in a post:
Send SIEM syslogs directly into the Huntress portal
D
Dan Sheather
We would like to be able to send SIEM syslog data directly from the firewall into the Huntress portal rather than relaying through an agent on the network.
Nate O'Brien
marked this post as
planned
Support for TLS encrypted Syslog over the internet to the Huntress portal is planned for release in early Q2.
A
Ashley Proctor
Another vote for this here, we have customers that don't have any fixed devices onsite, so is totally reliant on select devices going into the to collect data.
Being able to configure directly on kit, or through API/Integrations via vendor cloud management would be a huge life saver on this front for us. For example an integration with Unifi Network (Official hosted controller) and Sonicwall NSM.
J
Jaimeet Jaimeet
We need this, as if a syslog collector goes offline, is replaced or gets the IP changed by a different department we would not be in the know till it might be too late.
Misty Kaizen
We would love to see this
B
Brian Manning
Ideally having a cloud syslog address that we could point syslogs to in the instances where the client has no dedicated server or system to collect something like the firewall logs would be really helpful.
W
Wilmar Maliepaard
We need this sooner rather than later, not all of our customers are intersted in buying a dedicated PC just for the Huntress log collector. By not having a dedicated pc we wont get 24 / 7 logging. So this is a must to ensure 24 / 7 firewall logging.
Nate O'Brien
Hi Dan Sheather and all, we would likely only be able to support this for firewalls with the ability to TLS encrypt the syslog messages, otherwise the firewalls would be sending sensitive cleartext messages across the internet. Would that be a viable solution for you? I know not all firewalls support TLS over TCP syslog unfortunately. The only alternative would be API integrations.
Mason Schmitt
Hi Nate O'Brien, we currently use rsyslog which supports TLS.
R
Robert Quick
This would be great. If the current agent goes off line, we lose the logs.
J
Jacob Wiley
This would be very much appreciated!
Load More
→