Configure SNMP Trap and Syslog Event Forwarding

BeyondInsight, Discovery Scanner, Password Safe, and Endpoint Privilege Management products can forward the following:

  • SNMP traps using versions 1, 2, or 3
  • Events through a syslog daemon

With this forwarding function, it is feasible to integrate critical event information directly into a NMS, SIM, NAC, or other log consolidation, or event management systems.

A standard SNMP MIB, EEYE-RETINA_ EVENT-MIB, is available for decoding traps at the destination and is located at C:\Program Files (x86)\BeyondTrust\Retina 5\Help\Snmp. On a U-Series Appliance with Server 2016, the path is slightly different: C:\Program Files (x86)\BeyondTrust\Retina\Help\Snmp.

This MIB is valid for BeyondInsight and Discovery Scanner.

You can configure SNMP and syslog event forwarding settings from the Connectors page. Both protocols work for all data aggregated by BeyondInsight and Discovery Scanner.

Enable SNMP Event Forwarding

  1. In the BeyondInsight console, go to Configuration > General > Connectors.
  2. In the Connectors pane, click Create New Connector.
  3. Enter a name for the connector.
  1. Select SNMP Event Forwarder.
  1. Leave Active (yes) enabled.
  2. Select an Output Format and provide the name of the SNMP Community.
  3. Provide the IP address and port for the SNMP Trap receiver.
  4. Select the events that you want to forward.
  5. Click Test Connector to send a test event message.
  6. Click Create Connector.

Enable Syslog Event Forwarding

  1. In the BeyondInsight console, go to Configuration > General > Connectors.
  2. In the Connectors pane, click Create New Connector.
  3. Enter a name for the connector.
  1. Select Syslog Event Forwarder.
  1. Leave Active (yes) enabled.
  2. Select an output format: NewLine Delimited, Tab Delimited, or Comma Delimited.
  3. Select an optional syslog facility from the list.
  4. Provide the required details for the syslog server:
    • Select the protocol: TCP, TCP-SSL, or UDP.
    • Enter Host Name and Port.
  5. Select the events that you want to forward.
  6. Click Create Connector.