FLEX USG 200 logs to a Synology syslog server

mat17
mat17 Posts: 45  Freshman Member
First Comment Friend Collector Fourth Anniversary
Hi there,

I have a USG flex 200 and a Synology server.
I want to use my Synology as a syslog server.

There is three configuration options in my Synology server to receive the syslog messages:
- BSD format
- IETF format
- custom format

As I don't know anything, I chose randomly BSD format.

From my laptop, an Ubuntu one, in this configuration my syslog coming from my laptop are well parsed on my Synology server.

But I have a problem for those ones coming from my USG:
If I choose a syslog format in the remote server configuration, my messages are not well parsed: for examples for the security rules blocked by the firewall, I have the src IP in the program column, and the remaining of the message in the message column.
If I choose the other option. CEF/Syslog, then I have nothing anynore in the program column, all the message in the message column but not separated (the message is concatenated by |).

Just wondering which configuration should I use to have the same behaviour than my laptop?
Should I consider using a custom format when receiving the syslog messages?
How can I reproduce a debian syslog format with my USG?

Thanks in advance for your help

All Replies

  • Zyxel_Jeff
    Zyxel_Jeff Posts: 1,247  Zyxel Employee
    100 Answers 500 Comments Friend Collector Fourth Anniversary

    Should I consider using a custom format when receiving the syslog messages?
    Hello @mat17

    May we know whether have you ever tried to set IETF or custom formats on the Synology syslog server to receive syslog which is from the USG Flex200 before? Is it working for you? Thanks.



    See how you've made an impact in Zyxel Community this year! https://bit.ly/Your2024Moments_Community

  • mat17
    mat17 Posts: 45  Freshman Member
    First Comment Friend Collector Fourth Anniversary
    Hello,

    I did not try a custom format as I don't know which format to apply (can't find it in the documentation, will reach them out).
    Using IETF did not change anything.

    Kind regards
  • Zyxel_Jeff
    Zyxel_Jeff Posts: 1,247  Zyxel Employee
    100 Answers 500 Comments Friend Collector Fourth Anniversary
    edited December 2022
    Hi @mat17

    Here are some questions would like to confirm with you:
    What is your Synology NAS mode name?
    What is a well-parsed syslog that you expect?
    Could you provide the Ubuntu laptop syslog that was received from Synology NAS to us via private message? 
    Could you provide BSD format syslog that was received from Synology NAS and its log format on USG Flex 200 are (1). Syslog (2).CEF/Syslog respectively to us via private message as well? 


    Could you explain how the custom format syslog format works on the Synology NAS server?

    Thanks.



    See how you've made an impact in Zyxel Community this year! https://bit.ly/Your2024Moments_Community

  • mat17
    mat17 Posts: 45  Freshman Member
    First Comment Friend Collector Fourth Anniversary
    Hello,

    Before sending you a private message, do screenshots are enough?


  • Zyxel_Jeff
    Zyxel_Jeff Posts: 1,247  Zyxel Employee
    100 Answers 500 Comments Friend Collector Fourth Anniversary
    Hello @mat17

    You could share screenshots with us by private message as well. Besides, may we know whether you ever configure a custom format on the Synology NAS Syslog server?  And do you ever consulted with the Synology support team to see whether they have any ideas or suggestions?  Thanks.


    See how you've made an impact in Zyxel Community this year! https://bit.ly/Your2024Moments_Community

Security Highlight