Centralized Syslog Server Recommendations

Dunky
Head in the Cloud

Centralized Syslog Server Recommendations

I have been asked to setup a centralized syslog server so am reaching out to see if anyone has any recommendations, or 'avoid at all costs' advice.

 

I envisage setting up in Azure so we only have one to cover every single site.

It needs to properly decipher the Meraki logs to identify the originating MX.

 

How do I get the events from the Security Centre sent to syslog?

The aim is to retain 6months of logs from the MX Event log and IDS.

 

Any hints n tips would be most welcome too.

 

TIA

4 Replies 4
Mloraditch
Kind of a big deal
Kind of a big deal

I don't have a recommendation on service as my company uses a MSSP who handles that, but here are the setup directions: https://documentation.meraki.com/General_Administration/Operate_and_Maintain/Monitoring_and_Reportin...

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
PhilipDAth
Kind of a big deal
Kind of a big deal

I like syslog on Ubuntu.  Free.

 

If you are dealing with a large amount of data and need a powerful search, then Splunk is a good option.

tyler_dami
Conversationalist

We used Graylog for a long time. it works great and is easy to configure on a Ubuntu VM. Its like Splunk, but free!

https://graylog.org/products/source-available/

Looks like they have a lot of paid options available now too.

mlefebvre1
Here to help

Splunk is fantastic for logging in general and now also has an API integration into Meraki that is quite useful, but Splunk is also expensive so its certainly not for everyone. 

Get notified when there are additional replies to this discussion.