Configuring Generic Log Capture
You can capture generic logs from your devices, which you can send to Stellar Cyber Customer Success. Stellar Cyber can use these logs to generate a custom log parser for your device. Note that Stellar Cyber cannot use these generic logs for generating alerts.
To send the logs to Stellar Cyber:
-
Configure your device to send logs to UDP port 5201.
-
Allow Stellar Cyber to collect a significant number (100 or more) of logs.
-
In Stellar Cyber, select Threat Hunting.
The Threat Hunting page appears with the Interflow Search tab open by default.
-
Set Indices as Syslog.
-
Search for
dev_type:generic_capture
.Stellar Cyber displays the captured logs.
-
Select to expand a record.
-
Scroll to raw and hover your cursor over its row.
-
Select Show column in the set of options that appears to add raw to the columns.
This causes the Raw column to appear not just for this row but the entire table.
-
Change the Items per page to a number large enough to encompass all of the logs.
-
Select to download the records.
-
Send the downloaded logs to Stellar Cyber Customer Success.
-
Configure your device to stop sending logs to port 5201.