Set up the export of device audit records to a syslog server

  1. Using the same account that you used to install UEM, open a command prompt and run the following commands to upload a device audit syslog CA certificate. The commands cannot contain any line breaks.
    SET BESRoot=C:\Program Files\BlackBerry\UEM
    
    SET KEYSTORE_PATH=<path_to_CA_certificate>
    
    java -cp “%BESRoot%\tools\lib\*” --add-exports java.base/sun.nio.ch=ALL-UNNAMED --add-exports java.base/jdk.internal.ref=ALL-UNNAMED --add-exports java.base/sun.security.provider.certpath=ALL-UNNAMED -Djava.library.path=“%BESRoot%\tools\lib\dll\x64” com.rim.platform.mdm.keymaster.KeyMaster -keystore “%KEYSTORE_PATH%” load -keystoreType DEVICE_AUDITLOG_SYSLOG_CACERTS -trusted -BESRoot “%BESRoot%”
  2. Run the following commands to configure mutual authentication and upload a device audit syslog client key pair. The commands cannot contain any line breaks.
    SET BESRoot=C:\Program Files\BlackBerry\UEM
    
    SET KEYSTORE_PATH=<path_to_device_audit_certificate>
    
    SET KEYSTORE_PASSWORD=<user_defined_password>
    
    java -cp “%BESRoot%\tools\lib\*” --add-exports java.base/sun.nio.ch=ALL-UNNAMED --add-exports java.base/jdk.internal.ref=ALL-UNNAMED --add-exports java.base/sun.security.provider.certpath=ALL-UNNAMED -Djava.library.path=“%BESRoot%\tools\lib\dll\x64” com.rim.platform.mdm.keymaster.KeyMaster -keystore “%KEYSTORE_PATH%” -password “%KEYSTORE_PASSWORD%” load -keystoreType DEVICE_AUDITLOG_SYSLOG_CLIENT -BESRoot “%BESRoot%”
  3. Prepare the script in Script to enable the export of device audit records to syslog:
    1. Change the hostname and port number to match your environment. For example:
      SET @v_hostname = 'localhost';
      SET @v_port = '514';  
    2. Set any syslog specific formatting attributes as described in the script.
  4. Execute the script against the UEM database.
  5. Restart the BlackBerry UEM Core service.