Collect syslog from firewalls, switches, and other network devices
Anything that can't run an agent ships its logs through your Discovery Agent — encrypted before it leaves your network.
- 1Make sure a Cybermatic Discovery Agent runs on a machine that's always on, on the same network as the devices (install guide: Settings → Device agents → Network discovery). If you already use network discovery, that machine is already your collector.
- 2When SIEM is active, the Discovery Agent automatically listens for syslog on port 514, UDP and TCP. There is no collector configuration to do.
- 3On each network device, find the remote syslog / logging server setting and enter the collector machine's IP address, port 514, protocol UDP (or TCP if offered). Examples: pfSense → Status > System Logs > Settings > Remote Logging; UniFi → Settings > System > Logging; Synology → Log Center > Log Sending; most Cisco → 'logging host <ip>'.
- 4Save, then generate any log-worthy event (sign in to the device's admin page). Within a minute the device appears on the SIEM portal's Log Sources page and its events are searchable.
- 5Logs travel in plain syslog only on your LAN — the collector forwards them to Cybermatic over encrypted HTTPS, authenticated by your discovery enrollment.
Tip: All plans support unlimited syslog devices. When configuring a device that allows you to select a logging level, Informational is generally recommended. It provides useful operational and security visibility without the excessive volume generated by Debug logging, which can quickly consume your daily GB allowance.