Monitoring Syslog Messages
1.
Provide the hostname or IP address of the destination to which you want to
forward the received Syslog message.
2.
Provide the UDP Port you are using for Syslog messaging.
Note: The default is UDP port 514.
3. If you want to retain the IP address of the source device, complete the
following steps:
a. Check Retain the original source address of the message.
b. If you want to designate a specific IP address or hostname as the
Syslog source, check Use a fixed source IP address (or hostname), and
then provide the source IP address or hostname.
c. If you want to spoof a network packet, check Spoof Network Packet,
and then select an appropriate Network Adapter.
d. Click OK to complete the configuration of your Syslog forwarding action.
Syslog Alert Variables
The following variables can be used in Syslog alert messages. Each variable must
begin with a dollar sign and be enclosed in curly braces as, for example,
${VariableName}. Syslog alerts also support the use of Node alert variables.
n
Syslog Date/Time Variables
n
Other Syslog Variables
Syslog Date/Time Variables
Syslog Date/Time
Variable
Description
${AbbreviatedDOW} Current day of the week. Three character abbreviation.
${AMPM}
AM or PM corresponding to current time (before or after
noon)
${D} Current day of the month
${DD} Current day of the month (two digit number, zero padded)
${Date} Current date. (Short Date format)
294