What's new
  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

AC66U - guide for setting up External logging

lurc

New Around Here
Hi.
I am looking to set up external logging for the AC66U. The idea is to ingest them in splunk. However I can not find a way to set up external logging in the web GUI.
Can anybody please help me with a guide on setting up external logging?
 
Hi.
I am looking to set up external logging for the AC66U. The idea is to ingest them in splunk. However I can not find a way to set up external logging in the web GUI.
Can anybody please help me with a guide on setting up external logging?

Administration -> System. Enter the IP of the remote syslog server on that page.
 
Thanks. I finally got a connection. Any way to route the traffic logs as well?

Enable firewall logging on the Firewall page. Logging will go to syslog.
 
Logging questions.

I need to log the entries listed under the "Connections" tab in the "System Log" page of the router configuration. How can I do this? I need the internal NATted address specifically so I can track down a particular system.

The reason I need this is that I have a number of systems on my network, some wireless and some wired. I can see dangerous traffic outbound on my external NIDS, but even if I turn the firewall logs on for "all" traffic I can't tell which internal system sent the traffic.

Thanks in advance!

JS
 
I need to log the entries listed under the "Connections" tab in the "System Log" page of the router configuration. How can I do this? I need the internal NATted address specifically so I can track down a particular system.

The reason I need this is that I have a number of systems on my network, some wireless and some wired. I can see dangerous traffic outbound on my external NIDS, but even if I turn the firewall logs on for "all" traffic I can't tell which internal system sent the traffic.

Thanks in advance!

JS

These aren't a realtime display you can monitor or a logfile getting dumped - it's a list generated by running the netstat-nat command. You can manually run the same command over Telnet.
 

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Back
Top