You can configure VAST Cluster to send event alarms to a syslog service running on any remote Linux host. To do this, you need to enable the communication protocol on the syslog service and configure the VMS syslog settings.
Configuring VMS Syslog Settings
To configure the VMS to send events to syslog:
To configure syslog server settings using the VAST Web UI, see Default Notification Actions
To configure syslog server settings using the VAST CLI, run
eventdefinitionconfig modify. For example:eventdefinitionconfig modify --syslog-host 192.0.2.0 --syslog-port 514 --syslog-protocol udp --enable-actions
Note
In this example, the option
--enable-actionsenables all configured default actions including syslog. They are enabled by default, but can be disabled. To view the current configuration and status of all default alarm actions, runeventdefinitionconfig showoreventdefinitionconfig list.
Syslog Event Example
An example VAST Cluster event written to the syslog server:
2020-05-20T08:20:09.619086+00:00 v2cn1 vast_event AUDIT - VMS - Manager: admin, create monitor