Essentials
...
- for Syslog over UDP: 514
- for Syslog over TCP: 514
- for Syslog over TLS: TCP 10514 (get root certificate and intermediate certificate to get TLS working)
- for RELP: TCP 20514
Authorization
There are two ways to authorize when you send logs. Authorizing means telling Logsene which Logsene App to send logs to. We recommend you embed your Logsene App token in your syslog daemon's config in a CEE-formatted JSON message. Step-by-step instructions for rsyslog and syslog-ng, and a raw example are below.
Alternatively, authorize your public IPs and then send messages directly. Note that configuring your log shipper to send your Logsene App token is preferred to authorizing source IPs. You can see specific instructions for rsyslog, syslog-ng and syslogd for how to forward messages in this case.
Example
A quick way to ship messages via TCP syslog is with netcat:
...