04-12-2019, 08:22 AM
Hi Rob,
[Technology - SIEM Tooling - 1.6.25 Secure Event Transfer - Support for secure event transfer and the actual implementation of secure transfer (e.g. regular syslog is not secure)]
My environment using UDP/514 (not even TCP
) when sending syslog from a firewall to SIEM.
For best practise, do you recommend rsyslog TLS or TLS/6514 or syslog-ng with encryption enabled?
Thanks!
[Technology - SIEM Tooling - 1.6.25 Secure Event Transfer - Support for secure event transfer and the actual implementation of secure transfer (e.g. regular syslog is not secure)]
My environment using UDP/514 (not even TCP

For best practise, do you recommend rsyslog TLS or TLS/6514 or syslog-ng with encryption enabled?
Thanks!