Collect Illumio Core logs
This document describes how you can collect the Illumio Core logs by using a Google Security Operations forwarder.
For more information, see Data ingestion to Google SecOps .
An ingestion label identifies the parser which normalizes raw log data to structured
UDM format. The information in this document applies to the parser with the ILLUMIO_CORE
ingestion label.
Create a log group
- In the Policy Console Engine (PCE)web console menu, go to Settings > Event settings.
- Click Add. The Event settings – add event forwardingwindow appears.
- Click Add repository.
-
In the Add repositorydialog that appears, do the following:
- In the Descriptionfield, enter a name for the syslog server.
- In the Addressfield, enter the IP address of the syslog server.
- In the Protocollist, select UDPor TCPas a protocol.
- In the Portfield, enter the port number for the syslog server.
- In the TLSlist, select Disabled.
- Click Ok
-
In the Eventsdialog that appears, choose the events you want to send to your syslog server.
-
Configure the event forwarding repository to specify the required events for forwarding.
-
Enable all options in Auditable eventsand Traffic events.
-
Click Save.
Configure the Google SecOps forwarder to ingest Illumio Core logs
- In the Google SecOps menu, select Settings > Forwarders > Add new forwarder.
- In the Forwarder namefield, enter a unique name for the forwarder.
- Click Submit. The forwarder is added and the Add collector configurationwindow appears.
- In the Collector namefield, enter a unique name for the collector.
- In the Log typefield, specify
Illumio Core. - Select Syslogas the Collector type.
- Configure the following input parameters:
- Protocol: specify the connection protocol that the collector uses to listen to syslog data.
- Address: specify the target IP address or hostname where the collector resides and listens to syslog data.
- Port: specify the target port where the collector resides and listens to syslog data.
- Click Submit.
For more information about the Google SecOps forwarders, see Manage forwarder configurations through the Google SecOps UI .
If you encounter issues when you create forwarders, contact Google SecOps support .

