Syslog Sender
Use the Syslog Sender integration to send messages and mirror incident War Room entries to Syslog.
Analytics & SIEM · Syslog
Details
| ID | Syslog Sender |
|---|---|
| Provider | Open Source |
| Category | Analytics & SIEM |
| From Version | 5.5.0 |
| Docker Image | demisto/syslog:1.0.0.10133006 |
| Supported Modules | Agentix XSIAM |
README
Overview
Use the Syslog Sender integration to send messages in RFC 5424 message format and mirror incident War Room entries to Syslog.
Use Cases
- Send messages to Syslog via TCP or UDP or TLS.
- Mirror incident war room entries to Syslog.
- Track any activity from the Playground and War Room to your SIEM for improved visibility. This activity should be logged and attributed to the specific analyst.
Configure Syslog Sender on Cortex XSOAR
Usage example for rsyslog
To allow sending messages to rsyslog via Cortex XSOAR, the following lines have to be in the rsyslog configuration:
For TCP:
module(load="imtcp")
input(type="imtcp" port="<port>")
For UDP:
module(load="imudp")
input(type="imudp" port="<port>")
Usage example for sending War Room/Playground actions to Syslog
- From the Incidents page, click an incident.
- Run the !mirror-investigation type=”all” command.
If you receive an Investication mirrored to Syslog successfully response, any action in the War Room will be sent to Syslog.
For example:
Run the command !Print value=”test msg”
<14>1 2023-09-19T13:49:38.140870+00:00 a1427a8493b5 SysLogLogger 1 - - 29, 105@29, admin: !Print value=" incident owner is ${incident.owner}"
<14>1 2023-09-19T13:49:38.162145+00:00 a4140f2eb707 SysLogLogger 1 - - 29, 106@29, DBot: incident owner is admin
Syslog already contains the analyst name - admin (the user who performed the action).
The action is: !Print value=”test msg”
The action result appears on the second line.
If you run the same command with a different user on the same Cortex XSOAR instance, the output will be:
<14>1 2023-09-19T13:56:02.152486+00:00 a1427a8493b5 SysLogLogger 1 - - 8069, 86@8069, jsmith: !Print value=" incident owner is ${incident.owner}"
<14>1 2023-09-19T13:56:02.180858+00:00 a4140f2eb707 SysLogLogger 1 - - 8069, 87@8069, DBot: incident owner is admin
Username (analyst) is present and located before each command. In this case, jsmith.
The timestamp is present and loacated at the beginning of each string.
To determine the execution time (duration), calculate the difference between the second timestamp and the first.
Integration configuration
- Navigate to Settings > Integrations > Servers & Services.
- Search for Syslog Sender.
- Click Add instance to create and configure a new integration instance.
- Name: a textual name for the integration instance.
- IP Address (e.g. 127.0.0.1)
- Port
- Protocol (TCP / UDP)
- Minimum severity of incidents to send messages on
- Log level to send
- Facility
- Long running instance. Required for investigation mirroring.
- Incident type
- Click Test to validate the URLs, token, and connection.
Commands
You can execute these commands from the Cortex XSOAR CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
- mirror-investigation
- send-notification
1. mirror-investigation
Mirrors the investigation’s War Room to syslog.
Base Command
mirror-investigation
Input
| Argument Name | Description | Required |
|---|---|---|
| type | The mirroring type. Can be “all”, which mirrors everything, “chat”, which mirrors only chats (not commands), or “none”, which stops all mirroring. | Optional |
Context Output
There is no context output for this command.
Command Example
!mirror-investigation
Human Readable Output
Investigation mirrored successfully.
2. send-notification
Sends a message to syslog.
Base Command
send-notification
Input
| Argument Name | Description | Required |
|---|---|---|
| message | The message content. | Optional |
| entry | An entry ID to send as a link. | Optional |
| ignoreAddURL | Whether to include a URL to the relevant component in Cortex XSOAR. Can be “true” or “false”. The default value is “false’. | Optional |
| level | Log level to send. Can be “DEBUG”, “INFO”, “WARNING”, “ERROR”, or “CRITICAL”. | Optional |
Context Output
There is no context output for this command.
Command Example
!send-notification message=Test ignoreAddURL=true
Human Readable Output
Message sent to Syslog successfully.
3. syslog-send
Send a message to Syslog
Base Command
syslog-send
Input
| Argument Name | Description | Required |
|---|---|---|
| message | The message content. | Optional |
| level | The log level to send. Can be “DEBUG”, “INFO”, “WARNING”, “ERROR”, or “CRITICAL”. | Optional |
| address | The Syslog server address. | Optional |
| protocol | The protocol to use | Optional |
| port | The Syslog server port (required for TCP or UDP protocols). | Optional |
| facility | The Syslog facility. | Optional |
Context Output
There is no context output for this command.
Command Example
!syslog-send address=127.0.0.1 port=514 protocol=TCP message=yo level=ERROR
Human Readable Output
Message sent to Syslog successfully.
Troubleshooting
Make sure you can access the Syslog server on the provided IP address and the port is open.
Demo Video
Sorry, your browser doesn't support embedded videos. You can download the video at: https://github.com/demisto/content-assets/blob/7982404664dc68c2035b7c701d093ec026628802/Assets/Syslog/syslog-sender-demo.mp4
Configuration parameters
address— IP Address (e.g., 127.0.0.1)port— Portprotocol— Protocolcertificate—self_signed_certificate— Self Signed Certificatefacility— Facilitypriority— Log level to sendseverity— Minimum severity of incidents to send messages on
Commands (3)
-
mirror-investigationMirrors the investigation's War Room to Syslog.
-
send-notificationSends a message to Syslog. Used by the mirroring functionality.
-
syslog-sendSends a message to Syslog.
category: Analytics & SIEM provider: Open Source sectionorder: - Connect - Collect commonfields: id: Syslog Sender version: -1 configuration: - display: IP Address (e.g., 127.0.0.1) name: address type: 0 section: Connect additionalinfo: A Syslog server address must be provided. Note, the maximal supported length of a label inside an address is 64 characters. required: false - defaultvalue: '514' display: Port name: port type: 0 section: Connect additionalinfo: When using UDP or TCP, port 514 is the default. When using TLS, port 6514 is the default. required: false - defaultvalue: UDP display: Protocol name: protocol options: - TCP - UDP - TLS type: 15 section: Connect advanced: true additionalinfo: TLS versions supported are 1.2 and above. required: false - name: certificate type: 9 section: Connect displaypassword: Certificate hiddenusername: true additionalinfo: Required for TLS. required: false - display: Self Signed Certificate name: self_signed_certificate type: 8 section: Connect additionalinfo: Required for TLS. Check if the certificate is self signed. required: false - defaultvalue: LOG_USER display: Facility name: facility options: - LOG_AUTH - LOG_AUTHPRIV - LOG_CRON - LOG_DAEMON - LOG_FTP - LOG_KERN - LOG_LPR - LOG_MAIL - LOG_NEWS - LOG_SYSLOG - LOG_USER - LOG_UUCP - LOG_LOCAL0 - LOG_LOCAL1 - LOG_LOCAL2 - LOG_LOCAL3 - LOG_LOCAL4 - LOG_LOCAL5 - LOG_LOCAL6 - LOG_LOCAL7 type: 15 section: Connect advanced: true required: false - defaultvalue: LOG_INFO display: Log level to send name: priority options: - LOG_DEBUG - LOG_INFO - LOG_WARNING - LOG_ERR - LOG_CRIT type: 15 section: Collect advanced: true required: false - defaultvalue: Low display: Minimum severity of incidents to send messages on name: severity options: - Unknown - Low - Medium - High - Critical type: 15 section: Collect required: false hidden: - marketplacev2 - platform description: Use the Syslog Sender integration to send messages and mirror incident War Room entries to Syslog. display: Syslog Sender name: Syslog Sender script: commands: - arguments: - auto: PREDEFINED default: true defaultValue: all description: The mirroring type. Can be "all", which mirrors everything, "chat", which mirrors only chats (not commands), or "none", which stops all mirroring. name: type predefined: - all - chat - none description: Mirrors the investigation's War Room to Syslog. name: mirror-investigation - arguments: - default: true description: The message content. name: message - description: An entry ID to send as a link. name: entry - auto: PREDEFINED defaultValue: 'false' description: Whether to include a URL to the relevant component in Demisto. Can be "true" or "false". The default value is "false'. name: ignoreAddURL predefined: - 'true' - 'false' - auto: PREDEFINED description: The log level to send. Can be "DEBUG", "INFO", "WARNING", "ERROR", or "CRITICAL". name: level predefined: - DEBUG - INFO - WARNING - ERROR - CRITICAL description: Sends a message to Syslog. Used by the mirroring functionality. name: send-notification - arguments: - description: The message content. name: message required: true - auto: PREDEFINED description: The log level to send. Can be "DEBUG", "INFO", "WARNING", "ERROR", or "CRITICAL". name: level predefined: - DEBUG - INFO - WARNING - ERROR - CRITICAL - description: The Syslog server address. name: address - auto: PREDEFINED description: The protocol to use. Can be "TCP", "UDP", or "TLS". name: protocol predefined: - TCP - UDP - description: The Syslog server port. name: port - auto: PREDEFINED description: The Syslog facility. name: facility predefined: - LOG_AUTH - LOG_AUTHPRIV - LOG_CRON - LOG_DAEMON - LOG_FTP - LOG_KERN - LOG_LPR - LOG_MAIL - LOG_NEWS - LOG_SYSLOG - LOG_USER - LOG_UUCP - LOG_LOCAL0 - LOG_LOCAL1 - LOG_LOCAL2 - LOG_LOCAL3 - LOG_LOCAL4 - LOG_LOCAL5 - LOG_LOCAL6 - LOG_LOCAL7 description: Sends a message to Syslog. name: syslog-send dockerimage: demisto/syslog:1.0.0.10133006 runonce: false script: '-' subtype: python3 type: python tests: - Test Syslog fromversion: 5.5.0