Skip to content
All guidesCybermatic SIEM

Collect syslog from firewalls, switches, and other network devices

Anything that can't run an agent ships its logs through your Discovery Agent — encrypted before it leaves your network.

  1. 1Make sure a Cybermatic Discovery Agent runs on a machine that's always on, on the same network as the devices (install guide: Settings → Device agents → Network discovery). If you already use network discovery, that machine is already your collector.
  2. 2When SIEM is active, the Discovery Agent automatically listens for syslog on port 514, UDP and TCP. There is no collector configuration to do.
  3. 3On each network device, find the remote syslog / logging server setting and enter the collector machine's IP address, port 514, protocol UDP (or TCP if offered). Examples: pfSense → Status > System Logs > Settings > Remote Logging; UniFi → Settings > System > Logging; Synology → Log Center > Log Sending; most Cisco → 'logging host <ip>'.
  4. 4Save, then generate any log-worthy event (sign in to the device's admin page). Within a minute the device appears on the SIEM portal's Log Sources page and its events are searchable.
  5. 5Logs travel in plain syslog only on your LAN — the collector forwards them to Cybermatic over encrypted HTTPS, authenticated by your discovery enrollment.

Tip: All plans support unlimited syslog devices. When configuring a device that allows you to select a logging level, Informational is generally recommended. It provides useful operational and security visibility without the excessive volume generated by Debug logging, which can quickly consume your daily GB allowance.

More in Cybermatic SIEM