Documentation forSecurity Event Manager

Set up a separate syslog server for use with SEM

This topic describes how to add a separate syslog server to SEM. The SEM VM includes a syslog server, but you can add a separate syslog server.

You can monitor your switches, routers, and firewalls using a syslog server. This server collects and sends syslog messages from non-Agent devices to the SEM Manager over TCP or UDP. SEM uses this information to monitor syslog events and displays them in the Live and Historical Events.

Each device is paired with a connector, enabling SEM to parse messages from the syslog server and normalize the log message content to a SEM event.

To set up a separate syslog server, you must deploy another SEM VM to function as a syslog server. Contact SolarWinds Customer Support for assistance.