Syslog configuration in the QRadar console
Use the information in the following table to verify the default CylanceRemoteSyslog settings.
- Go toSettings > Admin > Log Sources > CylanceRemoteSyslog > Edit.
- The expected CylanceRemoteSyslog log source configuration is as follows.ItemSettingLog source nameCylanceRemoteSyslogLog source descriptionCylance: Connection to Cylance TenantLog source typeCylanceProtocol configurationTLS SyslogLogSource identifiersysloghostTLS listen port6514Authentication modeTLSCertificate typeGenerate CertificateTLS protocolTLS 1.2 and aboveEnabledCheckedCredibility10Coalescing eventsUncheckedStore event payloadCheckedLog source extensionCylanceCustom_extEnable multilineFalse