Collect Illumio Core logs
This document describes how you can collect the Illumio Core logs by using a Google Security Operations forwarder.
For more information, see Data ingestion to Google SecOps.
An ingestion label identifies the parser which normalizes raw log data to structured
UDM format. The information in this document applies to the parser with the
ILLUMIO_CORE
ingestion label.
Create a log group
- In the Policy Console Engine (PCE) web console menu, go to Settings > Event settings.
- Click Add. The Event settings – add event forwarding window appears.
- Click Add repository.
In the Add repository dialog that appears, do the following:
- In the Description field, enter a name for the syslog server.
- In the Address field, enter the IP address of the syslog server.
- In the Protocol list, select UDP or TCP as a protocol.
- In the Port field, enter the port number for the syslog server.
- In the TLS list, select Disabled.
- Click Ok
In the Events dialog that appears, choose the events you want to send to your syslog server.
Configure the event forwarding repository to specify the required events for forwarding.
Enable all options in Auditable events and Traffic events.
Click Save.
Configure the Google SecOps forwarder to ingest Illumio Core logs
- In the Google SecOps menu, select Settings > Forwarders > Add new forwarder.
- In the Forwarder name field, enter a unique name for the forwarder.
- Click Submit. The forwarder is added and the Add collector configuration window appears.
- In the Collector name field, enter a unique name for the collector.
- In the Log type field, specify
Illumio Core
. - Select Syslog as the Collector type.
- Configure the following input parameters:
- Protocol: specify the connection protocol that the collector uses to listen to syslog data.
- Address: specify the target IP address or hostname where the collector resides and listens to syslog data.
- Port: specify the target port where the collector resides and listens to syslog data.
- Click Submit.
For more information about the Google SecOps forwarders, see Manage forwarder configurations through the Google SecOps UI.
If you encounter issues when you create forwarders, contact Google SecOps support.