Create Syslog for select events

Syslog
stands for System Logging Protocol and is a standard protocol used to send system log or event messages to a specific server, called a syslog server. It is primarily used to collect various device logs from several different machines in a central location for monitoring and review. It allows the separation of the software that generates messages, the system that stores them, and the software that reports and analyzes them. Each message is labeled with a facility code, indicating the software type generating the message, and assigned a severity level.
Starting from version 6.21.00,
FactoryTalk Linx
could generate SysLog for select events including CIP Security configuration changes, network configuration changes, and system powerup. Then the Syslog messages can be displayed in the Syslog server.
Prerequisite
  • Ensure the devices that apply syslog are added in the same zone in
    FactoryTalk Policy Manager
    .
To enable and configure the Syslog server
  1. In the
    Start
    menu, select
    Rockwell Software
    >
    FactoryTalk Policy Manager
    .
  2. In
    Global Settings
    , select
    Enable security eventing using Syslog server
    .
  3. In
    Sever Settings
    ,
    • Select IP Address or Hostname.
    • Enter the Port number and Protocol.
  4. In
    Filter Settings
    , specify
    Event types that will generate messages
    and
    Lowest level of severity to log
    .
  5. In
    Message Settings
    , specify the
    Sequence ID
    ,
    Time quality
    , and
    Time resolutions
    .
  6. Click
    Deploy
    .
FactoryTalk Linx
could generate SysLog for CIP Security configuration changes, network configuration changes, and system powerup. The table below lists the detailed events that
FactoryTalk Linx
supported.
Category
Events
CIP Security configuration changes
  • A new CRL for CIP Security was received.
  • A new CIP Security identity was received.
  • A new CIP Security identity failed to be accepted.
  • A new policy was configured.
  • Failed to start CIP Security messaging session.
  • Started CIP Security messaging session.
  • CIP Security trust was modified.
Network configuration changes
  • Failed to modify network configuration.
  • Network configuration was modified.
System powerup
Restart the
FactoryTalk Linx
service.
Provide Feedback
Have questions or feedback about this documentation? Please submit your feedback here.
Normal