Syslog Logs

Connecting Syslog logs to your Panther Console

Overview

Panther supports ingesting Syslog logs via common Data Transport options: Amazon Web Services (AWS) S3, SQS, and CloudWatch.

How to onboard Syslog logs to Panther

To connect these logs into Panther:

  1. In the left-hand navigation bar of your Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search for the log type you want to onboard, then click its tile.

  4. Select the data transport method you wish to use for this integration, then follow Panther's instructions for configuring the method:

  5. Configure Syslog to push logs to the Data Transport source.

    • Consult your Syslog documentation for guidance on pushing logs to the Data Transport source of your choice.

Implementing Syslog onboarding is contingent upon the use of a log forwarder.

Supported log types

For Syslog logs ingested via Fluentd, please refer to the Fluentd Syslog schemas.

Syslog.RFC3164

Syslog parser for the RFC3164 format (ie. BSD-syslog messages)

Reference: Syslog Documentation on RFC3164 BSD Protocol.

Syslog.RFC5424

Syslog parser for the RFC5424 format.

Reference: Syslog Documentation on RFC5424 Protocol.

Last updated

Was this helpful?