How to enable Sangfor Endpoint Secure Syslog?

Newbie479522 Lv1Posted Aug-11-2025 10:13

Hi Sangfor community, our team is attempting to integrate Sangfor Endpoint Secure to a SIEM via syslog. But upon checking the interface of the solution, we can't seem to find any setting to enable or setup the syslog service.

How to enable syslog? Endpoint Secure is SaaS and version is ES 6.0.4.

Thank you.

Newbie517762 has solved this question and earned 10 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

HiHi,

You can locate the "Enable syslog sync" option in System\Data Sync\Syslog Reporting:
Please find the detailed settings in the attached file.
EPP_Syslog.pdf (202.09 KB, Downloads: 152)
Is this answer helpful?
Sangfor Jojo Lv5Posted Aug-12-2025 08:57
  
The following answer is gernerated by Sangfor AI assistant "Solvia".
--------------------------------------------------------------------------------------------------------------------------------------

Enabling Syslog in Endpoint Secure:
1. Access the Endpoint Secure Interface:

    Log in to your Endpoint Secure web interface.

2. Navigate to Syslog Reporting Settings:
     -Go to System in the main menu.
     -Select Data Sync.
     -Click on Syslog Reporting.

3. Enable Syslog Server Backup:

    In the Syslog Reporting section, you will find an option to enable Syslog Server Backup. Make sure to check this option.

4. Configure Syslog Server Details:

    Fill in the corresponding Syslog server’s IP address and port. The default port for syslog is typically UDP 514.
    Ensure that you check the corresponding backup log content that you wish to forward.

5. Save the Configuration
:

    After entering the necessary details, make sure to save the configuration.

Important Notes:
  • As of version 6.0.2R1, the syslog outbound log format is in JSON format, and it supports three encoding formats: Unicode, UTF-8, and GBK.
  • Ensure that your Endpoint Secure version supports syslog forwarding. Since you are using version 6.0.4, it should support this feature as it is above the required version.
  • If you encounter any issues, verify that the syslog server is reachable from the Endpoint Secure instance and that there are no firewall rules blocking the traffic.


Newbie517762 Lv5Posted Aug-12-2025 09:07
  
HiHi,

You can locate the "Enable syslog sync" option in System\Data Sync\Syslog Reporting:
Please find the detailed settings in the attached file.
EPP_Syslog.pdf (202.09 KB, Downloads: 152)
Newbie479522 Lv1Posted Aug-13-2025 10:06
  
Last edited by Newbie479522 Aug-13-2025 10:14.

Thank you for all the detailed answers and instructions. It is highly appreciated.

All your answers were right, it seems the data sync part needs to be enabled first by Sangfor back-end support for it to show or be seen on the EDR interface.

I Can Help:

Change

Moderator on This Board

2
1
0

Started Topics

Followers

Follow

1
1
0

Started Topics

Followers

Follow

909
182
94

Started Topics

Followers

Follow

Trending Topics

Board Leaders