Send Sangfor NGAF Log to Elasticsearch

Newbie405830 Lv1Posted 17 Jan 2024 10:46

Hello,

Have anyone ever sent logs from Sangfor NGAF to Elasticsearch or Elk Stack? How to send sanfor NGAF log to elk.?

Please share your experince or any other option for syslog except kiwi syslog with best open source log server.?

Thanks

Newbie517762 has solved this question and earned 10 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Last edited by Newbie517762 17 Jan 2024 11:18.

HiHi,

Please find below the relevant information for your easy reference:
Sangfor NGAF Syslog Configuration Guide:


- Select the Logging Location to Syslog for Security Logs, Application Control Logs, Traffic Audit Logs, NAT Logs, User Authentication Logs, SSL VPN Logs, Local ACL Logs, and HA Error Logs.
The Syslog Server IP Address is 10.10.10.10, and the Port is 514.

- Configure the Syslog server. In this guide, we use Kiwi Syslog Service Manager as an example. Download and install Kiwi Syslog Service Manager at: https://www.kiwisyslog.com



Is this answer helpful?
NandangGozali Lv1Posted 17 Jan 2024 11:08
  
Hi,

Thank you for reply, but my concern is not the how to config syslog on NGAF..but especially how to parse the log from NGAF so elasticsearch will consume log from NGAF or may be another syslog server except kiwi syslog.

Thanks.

I Can Help:

Change

Moderator on This Board

0
2
4

Started Topics

Followers

Follow

67
14
3

Started Topics

Followers

Follow

3
1
2

Started Topics

Followers

Follow

1
131
3

Started Topics

Followers

Follow

Board Leaders