Hello,
I have multiple devices configured to send logs to my server logs (SIEM) and I need to keep all these logs of my devices for 2 years, for query and reports futures.
I have the following devices: routers, switches, firewalls, to send logs to my SIEM and I would like to know how I set SIEM to save to in your hard disk a structure as this:
Can I create a Logs file per device?
Can I create a Logs file per group (Client1, Client2, ...)?
Can I create a Logs file per type device (All firewalls, All routers, ...)?
What do you recommend me?
and how can I do?
SIEM1
Inicio de sesion
Cerrar sesion
Logones fallidos
Updrages
...
..
.
Client1
Firewalls
PA1_IP
Inicio de sesion
Cerrar sesion
Logones fallidos
...
..
.
PA2_IP
Routers
RT1_IP
RT2_IP
Switchs
SW1_IP
sw2_IP
Windows Server_IP
Linux Server_IP
...
..
.
Client2
Client3
Client4
...
..
.
Thank you very much
Diego