Audit Collection Syslog Gateway™

Fully leverage the Audit Collection Service (ACS) and optimize your auditing infrastructure for cross-platform event collection. Using the Audit Collection Syslog Gateway™ you can easily centralize collection of Windows and Syslog security events.

The Syslog Gateway includes a generic audit report that enables users to filter on syslog messages strings and schedule report subscriptions based on those filters. In addition the Gateway includes a Management Pack for implementing custom alerting and operational views. Licensed like a Connector, the Syslog Gateway does not require per device licenses; it is priced per Gateway Server. 

Solution Resources

Solution Features

Gateway Architecture

The Syslog Gateway can be located on an existing ACS Collector or stand alone Windows Server 2003 or higher system. Syslog forwarding must be enabled from the endpoint devices to the Gateway Server.

Syslog Event Processing

Syslog events are processed by a common provider that maps syslog event strings to Windows Security event attributes.

Event Translation Process
1) Syslog enabled devices forward events to Gateway
2) Gateway Service recieves new events and writes them to local Windows Security log
3) The ACS Forwarder collects new events and sends them to Collector for processing

Operations & Reporting

The Audit Collection Syslog Gateway includes a generic Report that enables users to filter on any syslog message pattern. In addition the Gateway includes a Management Pack that provides canned Alert Rules and operational Views. Quickly setup subscriptions and overrides to enable your audit requirements.

Report Features
1) Expression Filter on Syslog Message
2) Online & Historical Reporting
3) Subscription Scheduling
MP Features
1) Generic Alert Rules on common syslog Events
2) Cisco Router & Firewall Alert Rules
3) Syslog Operational Views

Frequently Asked Questions

How is the Syslog Gateway licensed?

The Audit Collection Syslog Gateway is licensed per Gateway Server.

The solution can be added with the 'Security Auditing' package and can also be bought separately.

How may devices can the Syslog Gateway receive events from?

This depends on the type of devices, what messages are flagged for event forwarding and average Events per Second (EPS). The Syslog Gateway can process an average of 1000 EPS.

If you have any questions, comments, need support or would like to place an order please contact us for assistance.

News & Events

Press Release 08/04/2009: Secure Vantage Releases Security Auditing SP2 for the Audit Collection Services (ACS)


Online Webcasts 06/08/2009: Download the ACS Master Class Series for free real world expert training on the Audit Collection Services.


Read more