Jump to content

Camilo Diaz

Members
  • Content Count

    11
  • Joined

  • Last visited

Profile Information

  • Location
    New Zealand
  1. Camilo Diaz

    ESMC7 - Extracting data

    Hi Eset community, is there a way to dynamically export information from ESCM7 such as active threaths, unresolved incidents, etc, in a given time frame? What I am trying to achieve is to extract this information to feed our reporting/analysis tool (grafana). We don't want to use csv files, as we'd have to manually import the file. Hope that's clear. Cheers Camilo
  2. Camilo Diaz

    ESMC7 - SYSLOG Server

    Windows uses Event Viewer. For using syslog, you need to set up a syslog server.
  3. Camilo Diaz

    ESMC7 - SYSLOG Server

    Ok so I just realized this won't work on a Windows server. I am pointing the syslog server to my PC running linux and I'll see if that makes a difference....
  4. Camilo Diaz

    ESMC7 - SYSLOG Server

    Ok, so for testing purposes I have set the server as localhost, that way I can send the JSON file to our syslog server. Do you know where those files are stored in Windows?
  5. Camilo Diaz

    ESMC7 - SYSLOG Server

    So this is my config of syslog server: This is the config for Logging I thought this last config will leave a copy in \ProgramData\ESET\RemoteAdministrator\Server\EraServerApplicationData\Logs\ ? If I set localhost as the host, where would the files be stored?
  6. Camilo Diaz

    ESMC7 - SYSLOG Server

    You should receive the logs in your syslog server. Because I didn't receive it, I began investigating by analyzing the network traffic to see what was going on but I can't see any traffic generated from Eset server to my syslog server :(.
  7. Camilo Diaz

    ESMC7 - SYSLOG Server

    Yes, exactly that. UDP and port 514. The same config is set in the web console. Do you have this configured?
  8. Camilo Diaz

    ESMC7 - SYSLOG Server

    Yes, I have the outbound firewall rule on the server but from the traffic capture I can't see any traffic going to my syslog server at all. Server is Microsoft Windows Server 2012 R2
  9. Camilo Diaz

    ESMC7 - SYSLOG Server

    Hi Eset, We currently have Eset Security management Center v7.0.553.0, configured to send the logs the a syslog server. I've captured the traffic from the server and I can't see any outbound traffic going to my log server. A special rule to allow the traffic is configured in the Firewall. Any ideas? Thanks, Camilo
×