i hope you help find a resolution for this:
I have a MARS 50, and i tried to add a Linux to send syslog messages to it. I added it, i can see the linux int the topology window.
I run a nmap scan on the linux, i get a lot of syslog messages on the linux console because of the nmap scanning, but the MARS doesn't show me any incidents.
I added the Linux host under Admin->Security and Monitor Devices -> Add -> Device Type: Add SW security apps on new host. Then i configured the ip, i chose Linux as the operating system and "Rceive" at the Logging Info.
I also configured the Linux to send syslog messages to MARS:
i added in the /etc/syslog.conf file, the next line:
Why don't i get messages from Linux?
Thank you for your time,