Configuring Secret Server Cloud
This section describes how to enable logging in Delinea Secret Server Cloud (SSC). Secret Server Cloud cannot directly send syslog or CEF logs to IBM QRadar. Audit events are forwarded to QRadar through a Distributed Engine installed on-premises.
-
Log in to Secret Server as Administrator.
-
Navigate to Admin > Configuration.
-
Scroll to the bottom and click Edit to start editing the configuration.
-
Select the Enable Web services checkbox
-
Configure Syslog/CEF Logging:
-
Go to Syslog / CEF Logging Advanced Settings
-
Select the Enable Syslog/CEF Logging checkbox.
-
Enter the hostname or IP address of the Distributed Engine.
-
Enter Port number 6514 (for TLS)
-
Select Protocol (TCP for TLS connections)
-
-
Click Save.