THE SAFEHOUSE / JOURNAL
rsyslog for SIEM Integration · Part 2 of 2

Part 2: Configuring /etc/rsyslog.conf for SIEM Integration

2 May 2025· 2 min read

In Part 1, we explored the significance of /etc/rsyslog.conf. Now, let's move to the hands-on section — configuring your Linux server to forward syslogs to a SIEM platform such as OTM and verifying the setup.

Requirements Before You Start


Step-by-Step Configuration

1. Login to Your Linux Server

Use an “admin” privileged account to log in.


2. Edit the rsyslog.conf File

Open the configuration file using vi editor:

vi /etc/rsyslog.conf

3. Add a Forwarding Rule

Locate a suitable section or scroll to the bottom and add:

#### begin forwarding rule ###
*.* @IP-Address:514
#### end of forwarding rule ###

Example:

*.* @[192.168.1.100]:514

4. Save and Exit

After editing:


5. Restart the Rsyslog Service

To apply the changes:

service rsyslog restart

Check if the service is running without errors:

service rsyslog status

Step-by-Step Verification

Command-line verification:
 Run tcpdump on the collector machine:

sudo tcpdump -i any host [LinuxServerIP] and port [Port No] -XX

This checks if syslog messages are arriving.

Platform Verification:
 Login to the OTM Platform GUI and check if the logs are being processed properly.

Conclusion

With a simple but careful configuration of /etc/rsyslog.conf, you can route crucial Linux server logs into your SIEM environment — strengthening your monitoring, security and compliance capabilities.

Remember: efficient logging is the foundation of a secure and well-monitored infrastructure.

Related reading