Syslogs & Field Effect MDR

Introduction

Many network management solutions are provided as 'Appliance Devices', which run a proprietary operating system with limited or no support for third-party applications. This often includes security software like the Field Effect Agent. To extend visibility to these devices, Field Effect network appliances are equipped to act as centralized syslog receivers.


Syslog is a standard format for the reporting of system events, and are supported by most operating systems, including appliance devices. Once collected, syslog messages can be used to monitor and validate the activity taking place, or to investigate ongoing or past incidents that may have occurred. For certain appliance devices, automatic ARO generation for suspicious activity observed in syslog events is supported (please see below for supported devices and ARO types).


Syslog ingestion is supported and enabled by default for physical Field Effect network appliances. Virtual appliances are currently not supported. To learn more about this, see our Help Center content on appliances.


This article covers the following topics: 

 

Configuring Syslog Forwarding

To take advantage of syslog ingestion with your Field Effect network appliance, please configure syslog forwarding on each source device to use your network appliance's internal IP address on UDP port 5514. Once forwarding has been configured, please reach out to support@fieldeffect.com to confirm with our Support team that your network appliance is receiving messages.


Enabling Syslog-based AROs

Automatic ARO generation support for syslog messages is currently limited to specific appliance devices and/or vendors. Currently, the following device types are supported:

  • SonicWall network edge devices
  • Fortinet network edge devices
  • Sophos network edge devices
  • ESXi hypervisor servers


Please see below for additional detail on ARO types available for these devices. If you would like to explore these capabilities, please reach out to support@fieldeffect.com.


Limited support is also available for custom syslog event monitoring. Please note that research and development time may be required, and support may not be possible for all device and/or message types.


Supported ARO Types

SonicWall:

ARO generation based on VPN authentication events. Options include:

  • ARO on any successful login
  • ARO on any failed login
  • ARO on brute force authentication patterns
  • ARO on authentication events matching frequently abused account names


Fortinet:

ARO generation based on firewall events or VPN authentication events. Options include:

  • ARO on any Intrusion Prevention System (IPS) event
  • ARO on any firewall virus detection event
  • ARO on any VPN authentication event from unauthorized geographic location
  • ARO on brute force authentication patterns


Sophos:

ARO generation based on VPN authentication events. Options include:

  • ARO on brute force authentication patterns


ESXi:

ARO generation based on host system and virtual machine events. Options include:

  • ARO on brute force remote authentication patterns
  • ARO on mass VM shutdown event
  • ARO on suspicious host command execution
  • ARO on host security tampering or untrusted software installation
  • ARO on suspicious VM kernel events


Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article