<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic BlueCoat SG810 Event Logging - Enterasys SIEM in Security</title>
    <link>https://community.extremenetworks.com/t5/security/bluecoat-sg810-event-logging-enterasys-siem/m-p/27606#M15</link>
    <description>Hi&lt;BR /&gt;
&lt;BR /&gt;
I like to receive through syslog to my SIEM the "event logging" generated by a BlueCoat SG810. I already configured the BlueCoat and in my SIEM, in LOG ACTIVITY, this is what appears&lt;BR /&gt;
&lt;BR /&gt;
Event Name:Unknown log event&lt;BR /&gt;
Low Level Category:Unknown Generic Log Event&lt;BR /&gt;
Event Description:Unknown Generic Log-only event&lt;BR /&gt;
PAYLOAD (utf): &amp;lt;25&amp;gt;Jun 03 15:01:52 ProxySG: 90000 NTP: Response received from wrong NTP Server: 199.91.133.52 is not ntp.bluecoat.com(0) SEVERE_ERROR ../ntp.cpp 479&lt;BR /&gt;
&lt;BR /&gt;
In "LogSource" the spurcedevice didn't appear although there is a logsourcetype "BlueCoat SG Appliance"&lt;BR /&gt;
&lt;BR /&gt;
Do I need to change or update anything in my SIEM (&lt;B&gt;7.7.2 Patch 2 (Build 636622 (7.2.0.636622))?&lt;BR /&gt;
&lt;/B&gt;&lt;BR /&gt;
Or I need to "extract the property" for these events.&lt;BR /&gt;
&lt;BR /&gt;
Gonzalo&lt;BR /&gt;
&lt;BR /&gt;</description>
    <pubDate>Tue, 03 Jun 2014 18:21:00 GMT</pubDate>
    <dc:creator>cos</dc:creator>
    <dc:date>2014-06-03T18:21:00Z</dc:date>
    <item>
      <title>BlueCoat SG810 Event Logging - Enterasys SIEM</title>
      <link>https://community.extremenetworks.com/t5/security/bluecoat-sg810-event-logging-enterasys-siem/m-p/27606#M15</link>
      <description>Hi&lt;BR /&gt;
&lt;BR /&gt;
I like to receive through syslog to my SIEM the "event logging" generated by a BlueCoat SG810. I already configured the BlueCoat and in my SIEM, in LOG ACTIVITY, this is what appears&lt;BR /&gt;
&lt;BR /&gt;
Event Name:Unknown log event&lt;BR /&gt;
Low Level Category:Unknown Generic Log Event&lt;BR /&gt;
Event Description:Unknown Generic Log-only event&lt;BR /&gt;
PAYLOAD (utf): &amp;lt;25&amp;gt;Jun 03 15:01:52 ProxySG: 90000 NTP: Response received from wrong NTP Server: 199.91.133.52 is not ntp.bluecoat.com(0) SEVERE_ERROR ../ntp.cpp 479&lt;BR /&gt;
&lt;BR /&gt;
In "LogSource" the spurcedevice didn't appear although there is a logsourcetype "BlueCoat SG Appliance"&lt;BR /&gt;
&lt;BR /&gt;
Do I need to change or update anything in my SIEM (&lt;B&gt;7.7.2 Patch 2 (Build 636622 (7.2.0.636622))?&lt;BR /&gt;
&lt;/B&gt;&lt;BR /&gt;
Or I need to "extract the property" for these events.&lt;BR /&gt;
&lt;BR /&gt;
Gonzalo&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 03 Jun 2014 18:21:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/security/bluecoat-sg810-event-logging-enterasys-siem/m-p/27606#M15</guid>
      <dc:creator>cos</dc:creator>
      <dc:date>2014-06-03T18:21:00Z</dc:date>
    </item>
  </channel>
</rss>

