Configuring log outsourcing to the Sekoia solution¶
Warning!
The procedure for setting up log outsourcing to Sekoia.io differs depending on whether you are in a CyberElements Bastion context.
Specific instructions for the product used will be provided.
Enable log redirection¶
Access the web interface of the Mediation Controller server with the /console URI.
Examples
If access to the Mediation Controller on its web IP address is 10.0.10.10, then the administration console is reached at https://10.0.10.10/console.
If the Mediation Controller is reachable by a DNS name, for example cyberelements-bastion.domain.local, then the administration console is reached at https://cyberelements-bastion.domain.local/console.
Access the Configuration work plan by clicking on the icon below:
Then click on the General Options tile:
Check the boxes Send platform events via syslog and Send video events to syslog:
Configure log redirection¶
Access the Mediation Controller server's web interface with the URI /system.
Examples
If access to the Mediation Controller on its web IP address is 10.0.10.10, then access to the system interface will use the URL: https://10.0.10.10/system.
If access to the Mediation Controller is possible with a DNS name, for example cyberelements-bastion.domain.local, then access to the system interface will use the URL: https://cyberelements-bastion.domain.local/system.
Important !
For any changes to the password, license, or certificates (SSL Router, Watchdog, and CyberElements Bastion client), connect to the actual IP address for clusters (RIP_MED_WEB_MASTER or RIP_MED_WEB_SLAVE).
Then access the log configuration in the Log Options menu:
To configure the logs:
- Check the box
Send events to a remote syslog server - Specify the address and port of the Sekoia log hub
- Select the TCP (recommended) or TLS transport protocol
- Check the box
Allow the organizations to send their events via syslog
Log redirection is now effective to your Sekoia log hub.
Configure Sekoia to interpret logs¶
It is possible to customize log processing on the Sekoia side as indicated in the following documentation: Sekoia Docs




