Forwarding destinations can be used to redirect payload to a different port .
However, as I recall reading somewhere, for Cisco ESA you would probably need several steps to achieve what you want :
* create a custom log source (maybe based on the type identifier) and map them to something so they are not unknown/stored
* use routing rules to redirect this to created forwarding destination (use the "Prefix a syslog header..." option - as the header is probably not RFC compliant)
* create TCP multiline log source (use selected TCP port you redirected to) to serve as a gateway log source (you should define aggregation type and pattern there)
* create needed log source (using Source Name Formatting string defined in the gateway log source as log source identifier for this one)
I think many had encountered challenges with Cisco ESA logging. I had noticed release notes for Async OS 13 mentioning support for CEF format via syslog, so if you have the option to update the source you could probably avoid some headache.
------------------------------
Dusan VIDOVIC
------------------------------
Original Message:
Sent: Fri July 24, 2020 11:05 AM
From: Jabez Daniel
Subject: Redirect incoming traffic
Hi All,
Is there a option to redirect syslog coming in 514 port to a different port(i want to route to 12468 port) for a particular source IP?
Is there any configuration i can do in Log Source , Routing rules or forwarding destination in the QRadar UI to achieve the same?
I basically want to combine multi-line logs coming from Cisco ESA(UDP on dport 514) to redirect to dport 12468(TCP multi-line syslog).
Thanks,
Jabez
------------------------------
Jabez Daniel
------------------------------