Skip to main content

Site CollectorSite Collector Administration Guide

Modify the Syslog Collector Configuration

In the Overview section in addition to viewing the status, trend, last day volume, and collector name, you can modify the Collector configuration by clicking the Collector instance. To modify the configuration for the Syslog Collector instance:

  1. On the Exabeam Security Operations Platform home page, click the Collectors tile.

  2. Select Site Collectors from the sub-menu.

    The Overview section displays status groups, last day average volume, and a list of Site Collectors.

  3. On the Overview tab, click the Syslog Collector instance for which you want to modify the configuration.

    Modify_Syslog1_1.png
  4. In the Event Type section, update the Syslog event type: Single Line or Multi-line.

    Modify_Syslog1_2.png
  5. In the Authentication section, update the protocol, UDP or TCP.

  6. Click Definition to edit the collector name, change the site collector instance, and update the port. After the updates, click Next. Then click Update.

  7. To stop or delete the Syslog Collector instance, in the upper right corner, click Stop or Delete. You can also upgrade or restart the collector.

    Modify_Syslog1_3.png

    Note

    You can start a Collector instance that is stopped, by clicking Restart.

    You can delete a Collector of which the status is 'Running'. You can delete a Site Collector instance of which the status is 'Setup Error' or 'Installation Error'.