Configure Cisco Catalyst Center to send logs to Arctic Wolf

You can configure to send the necessary logs to Arctic Wolf® for security monitoring.

These resources are required:

  • An activated Capteur Arctic Wolf or Collecteur de journaux virtuel (vLC)
  • Administrator permissions for the UI

Configure a syslog server in Catalyst Center

Add your Capteur Arctic Wolf as a syslog destination in .

  1. Sign in to .
  2. From the main menu, click System > Settings > External Services > Destinations > Syslog.
  3. Click Add (+).
  4. In the Name field, enter a name for the syslog server.
  5. In the Description field, enter a brief description of the syslog server.
  6. In the Hostname/IP Address field, enter the IP address of your Capteur Arctic Wolf.
  7. In the Port field, enter 514.
  8. In the Protocol field, select TCP or UDP.
  9. Optional: Click Validate to test the configuration.
    After your configuration succeeds, a validation message appears.
  10. Click Save.

Export audit logs to syslog servers

Configure to forward audit logs to the syslog server you created.

  1. From the main menu, click Activities > Audit Logs.
  2. At the top of the page, click Edit (pencil icon).
  3. Select the syslog server that you configured in Configure a syslog server in Catalyst Center.
  4. Click Save.

Provide configuration information to Arctic Wolf

  1. Sign in to the Portail unifié Arctic Wolf.
  2. In the navigation menu, click Tickets & Alerts > All Tickets.
  3. Perform the appropriate action, depending on if you are:
    • A new customer — In the Ticket Type list, select Onboarding. Then, click the existing [Deploy] Site Config: <ticket_subject> ticket.
    • An existing customer — Click Open a New Ticket.
  4. On the Open a New Ticket page, configure these settings:
    • What is this ticket related to? — Select General request.
    • Subject — Enter Syslog changes.
    • Related ticket (optional) — Keep empty.
    • Message — Enter this information for your Concierge Security® Team (CST):
      • Confirmation that you completed the steps in this configuration guide.
      • The IP address or hostname of the Capteur Arctic Wolf that you used during the configuration.
      • The IP address, timezone, and device type for all sources that you are forwarding.
      • Questions or comments that you have.
  5. Click Send Message.

    Your CST reviews the details to make sure that Arctic Wolf is successfully processing the logs.