Skip to main content

Hello,
I would like to know if there is a difference between integrating a Linux server using the bindplane agent and not through syslog?

That is, is there any difference in the display of UDM fields, parsing, or any other log processing features?

This is Craig with Bindplane. Happy to answer your question.

If you are using the BP agent, you will read in data unparsed and set the parser type with the SecOps standardization processor: https://bindplane.com/docs/resources/processors/google-secops-standardization

It is also possible to send syslog to the Bindplane agent using the TCP or UDP Raw source.

NIX_SYSTEM is likely the parser to set with Ingestion Label for your use case.  

Final point, it is possible to configure the Bindplane agent headlessly, but I recommend using either Bindplane SaaS or self hosted deployments to quickly create those configurations. Entitlement is included with SecOps via our partnership with Google. 

I walkthrough setup of a Linux AuditD example in this Quick Start guide: https://bindplane.com/docs/how-to-guides/google-secops-bindplane-quick-start

Let me know if you have other questions! 

 


And this might help too https://www.youtube.com/watch?v=vLh0e18E5E0


Reply