You can use this document to learn about the specific, high-level steps needed to obtain Log Relay, and send additional log types to Armor's Security Information & Event Management (SIEM).
|
Before you begin: For Armor Enterprise Cloud users, you must already have a virtual machine in your account
For Armor Anywhere users, you must already have downloaded and installed the Armor Agent.
|
For introductory information on Log Relay, see Introduction to Log Relay. |
When you convert a virtual machine into a Log Relay device, your virtual machine / device will still contain the default Armor Agent components, such as FIM, Malware, Patching, etc. |
|
After you have converted your virtual machine into a Log Relay device, see Create and Configure Remote Log Sources to learn how to create and configure a remote log source.
TroubleshootingIn general, if you are having issues adding Log Relay to a remote log device, consider that: You need to update your permissions in AMP.
|
To add the above-mentioned AMP permissions to your account, see Roles and Permissions. |