Configuring Cylance to forward syslog to Precinct:
- Login to the Cylance console
- Select Settings > Application
- Click the Syslog/SIEM checkbox
- Select the Event Types for which you want to receive messaging
- Select or type in the information for your Syslog or SIEM integration. (Set the IP and port 514/tcp of the Precinct Streamer or All-In-One appliance)
- Make sure TLS/SSL box is NOT checked.
- If shipping with TLS is preferred, make sure port used is 6514/tls
- Click Test Connection to verify that your settings are correct
- Click Save
Cylance Syslog Guide v2.0