Skip Navigation

Syslog configuration in the QRadar console

Use the information in the following table to verify the default CylanceRemoteSyslog settings.
  1. Go to
    Settings > Admin > Log Sources > CylanceRemoteSyslog > Edit
    .
  2. The expected CylanceRemoteSyslog log source configuration is as follows.
    Item
    Setting
    Log source name
    CylanceRemoteSyslog
    Log source description
    Cylance: Connection to Cylance Tenant
    Log source type
    Cylance
    Protocol configuration
    TLS SyslogLog
    Source identifier
    sysloghost
    TLS listen port
    6514
    Authentication mode
    TLS
    Certificate type
    Generate Certificate
    TLS protocol
    TLS 1.2 and above
    Enabled
    Checked
    Credibility
    10
    Coalescing events
    Unchecked
    Store event payload
    Checked
    Log source extension
    CylanceCustom_ext
    Enable multiline
    False