If you have a Syslog Ingester deployed in your environment, you can use this Advanced Setting to apply listener configurations to it. For information on installing your Syslog Ingester, please refer to the following article:
How to Install the Syslog Ingester | ThreatLocker Help Center
After you have installed the Syslog Ingester on the machine, navigate to the 'Advanced Settings' page.

From here, select the '+ New Setting' button from the page's top left corner.

Selecting this button will open a side panel titled 'Create Settings'. From here, select the 'Listener Configurations' setting type.

Selecting this option will change the 'Applies To' options to only the groups with the 'Ingester' group type. You can choose your preferred computer or group from here.

Under the 'Parameters' section, you will now be given an area to input your Listener Configurations.

- The IP Address you will be listening on
- Please note that inserting 0.0.0.0 means ALL IPs.
- Port Number
- Action Type - Allows you to select between two options:
- Network - Select this option if your Syslog is a firewall.
- Other - Select this option if your device is not a firewall.
- Source Type - Allows you to select between three options:
- General SysLog
- Big-IP
- Meraki
Note: Your device must match Big-IP or Meraki if you choose one of those two options, otherwise the Unified Audit logging won't work. If your device is not from either of those vendors, select 'General SysLog'.
- Source - Syslog Listener asset name.
- This name will appear in the Unified Audit in the 'Asset Name' field.
- Allows you to add a new listener.
- Selecting this option will create another Listener Configurations section to input new information.

Note: It is recommended to use different ports for each listener you configure to avoid confusion when viewing the logs.
Select the 'Save' button at the bottom of the page after entering all of this information.

Once this has been appropriately configured, you will receive logs from the Syslog Ingester to your Unified Audit. They will be visible by the asset name configured in the 'Advanced Setting' and will be the action type of Network.
Help Center