Article describes how to setup Anybus Defenders to use Syslog to send their log files to a syslog server. The article includes an example how to setup a syslog server on Ubuntu Linux server.
Ensure that Anybus Defender can reach the syslog server. Under "Status" -> "System Logs"
Navigate to the "Settings" tab
Scroll down to "Remote Logging Options" and check "Enable Remote Logging" if it's not
Set the IP address of "Remote log servers" to what device are receiving the logs.
NOTE: Up to 3 simultaneous destinations for the log files can be configured.
Remote Syslog Contents can be specified in what type of logs. For this use-case, "Everything" was selected and logged.
How to configure Syslog server in Ubuntu (Linux rsyslog)
Install rsyslog to Linux with terminal
sudo apt install rsyslogstart rsyslog.service
sudo systemctl start rsyslogIn file path
/etc/rsyslog.confEdit with either
sudo nano /etc/rsyslog.confor preferred IDE
Remove commenting ("#") on "imuxsock", followed by adding an input. Add a filtering rule using if statement (Rainerscript) to send traffic in a specific path
#module(load="imuxsock") # provides support for local system logging
#input(type="imuxsock" port="514")
if $fromhost-ip '10.10.10.10' then {
action(type="omfile" file="/var/log/Anybus.log")
}
#module(load="imklog") # provides kernel logging support
#module(load="imudp")
#input(type="imudp" port="514")
#module(load="imtcp")
#input(type="imtcp" port="514")Save and exit the IDE
Rsyslog should receive connections on any IP address (0.0.0.0), usually with default port (514).
To display what ports the server is listening on, run
sudo ss -tulpn | grep rsyslogRecommended: If firewall is enabled, run
sudo ufw allow <port>/<protocol>Find syslog with
sudo tail -f /var/log/syslog Logs sent from device which filter rule it belongs to will be in the path specified
"file=/var/log/Anybus.log"View its contents with
sudo tail -f /var/log/Anybus.log