This article shows administrators how to send the StorageGuard application log (rg0) and the security log to an external syslog collector, such as a SIEM, by adding Java parameters to the Tomcat service.
APPLIES TO: STORAGEGUARD 10.X+
In this article
Before you begin
- Administrator access to the server running the StorageGuard Tomcat service.
- The hostname or IP address of your syslog collector, and the port it listens on.
- Network access from the StorageGuard server to the collector on that port - TCP 514 by default.
- A maintenance window. The change only takes effect after the Tomcat service is restarted.
Open the Tomcat service configuration
- Sign in to the StorageGuard server as an administrator.
- Open the Tomcat service manager,
tomcat10w.exe, from thebinfolder of your StorageGuard installation. - Select the Java tab. Parameters go in the Java Options box, one per line.
Tip: Leave the service manager open while you work through the next two sections — application and security log parameters go in the same box.
Forward the application log (rg0)
Add the following lines to Java Options, replacing the host value with your collector:
-Dcontlogger.syslog.host=syslog.example.com -Dcontlogger.syslog.port=514
Forward the security log
The security log uses its own parameter set. Add these lines as well if you want security events forwarded:
-Dcontlogger.sec.syslog.host=syslog.example.com -Dcontlogger.sec.syslog.port=514
Note: Both ports default to 514. If your collector listens on the default port, you can omit the port parameter entirely and set only the host.
Click Apply, then go to the General tab and restart the service: Stop, wait for the status to change, then Start.
Caution: Restarting Tomcat makes StorageGuard unavailable for the duration of the restart. Schedule it outside scan windows.
Use environment variables instead
If you manage server configuration centrally, you can set the same values as system environment variables rather than Java options. Use the parameter name without the leading -D:
contlogger.syslog.host=syslog.example.com contlogger.sec.syslog.host=syslog.example.com
This applies to every parameter in this article, including the advanced settings below. Restart the Tomcat service afterwards either way.
Verify it worked
Once the service is back up, generate an event — signing in to StorageGuard writes to the security log — and check your collector for messages from the StorageGuard server's hostname. Entries should appear within a minute of the event.
Advanced settings
The parameters below control severity, transport and message formatting. The defaults suit most deployments, and you only need to set a parameter if you are changing it. Add them to Java Options alongside the host and port values, then restart the service.
Application log (rg0)
| Parameter | Default | What it controls |
|---|---|---|
| contlogger.syslog.level | ERROR | The minimum severity forwarded. Lowering this increases message volume considerably. Possible values: INFO, WARNING, ERROR. |
| contlogger.syslog.facility | LOCAL0 | The syslog facility messages are tagged with, used by collectors for routing and filtering. |
| contlogger.syslog.protocol | TCP | The transport used to reach the collector. |
| contlogger.syslog.appName | cs-suite | The application name that identifies StorageGuard messages at the collector. |
| contlogger.syslog.cert.trust.store | — | Path to the trust store holding your collector's certificate. Required for encrypted delivery. |
| contlogger.syslog.cert.trust.store.pass | — | Password for that trust store. |
Security log
| Parameter | Default | What it controls |
|---|---|---|
| contlogger.sec.syslog.level | INFO | The minimum severity forwarded from the security log. Possible values: INFO, WARNING, ERROR. |
Note: The two logs forward at different levels by default. The application log sends ERROR and above, so a healthy system produces very little traffic on it. The security log sends INFO and above.
Troubleshooting
| Symptom | What to do |
|---|---|
| No messages reach the collector. | Confirm the service was restarted after the change. Then check that the collector's hostname resolves from the StorageGuard server and that the port is open — firewalls commonly block 514. |
| Security events arrive, but the application log looks empty. | Expected on a healthy system: the application log only forwards ERROR and above. Confirm the parameters are correct, then lower contlogger.syslog.level if you need more detail. |
| The Tomcat service won't start after the change. | A malformed Java option will block startup. Reopen Java Options and confirm each parameter is on its own line, begins with -D, and has no spaces around the =. |
Still need help?
Open a ticket from the Core6 Support portal. Include your StorageGuard version, the parameters you added, and whether the Tomcat service restarted cleanly.
Comments
0 comments
Please sign in to leave a comment.