Skip to content

Syslog

Syslog Settings

Use the Syslog page to configure automatic forwarding of Lockfy syslog events to a SIEM solution or centralized logging server such as Graylog. This allows external log analysis and correlation systems to receive Lockfy-generated security and operational events.

If you need HTTP-based event delivery instead of syslog forwarding, see Webhooks.

The page includes a single configuration form with the following settings:

  • Enable: Turns syslog forwarding on or off.
  • Protocol: Selects the transport protocol.
  • Server IP: The address of the destination syslog server.
  • Port: The destination port used by the syslog listener.
  • Format: Selects the syslog message format.
  • Frame: Selects how syslog messages are delimited.
  • Use TLS: Enables encrypted transport when supported by the destination.

Select Save after changing the configuration.

The supported protocol values are:

  • TCP
  • UDP

Choose TCP when reliable delivery is required and your logging platform expects stream-based transport.

Choose UDP when your logging pipeline is configured for connectionless syslog delivery.

The supported syslog formats are:

  • RFC5424
  • RFC3164

Choose the format required by your SIEM or syslog receiver.

The supported framing options are:

  • CRLF
  • CR
  • LF
  • NUL
  • OCTET_COUNTING

These options control how messages are terminated or framed when they are sent to the receiving system.

Configure this page to match the exact listener settings expected by your SIEM or syslog server. If the remote platform requires encrypted transport, enable Use TLS and verify that the selected protocol and framing method are supported by that destination.

After saving the configuration, confirm on the receiving system that Lockfy events are arriving and being parsed correctly.