You run the network for Brightwater Outfitters, a small outdoor-gear shop.
The edge appliance bw-edge-01
keeps logs only on the box, and its local file rolls over so fast that yesterday's
events were already gone by morning. If the appliance reboots — or someone tampers
with it — the evidence vanishes with it.
Set sane local retention, then forward the events that matter to the shop's central
log collector, logvault.brightwater.lan
at 10.20.5.40, so the logs survive off-box. Forward only the
System and Firewall facilities — not the chatty everyday noise.
Authenticate to the management console to change logging settings.
Lab credentials — netadmin / Tr@ilGuide!26
Control how much history the appliance keeps on its own storage and how many entries it shows per page.
Send a copy of selected events to an off-box collector so they survive a reboot, failure, or tamper.
Q1. By default, which transport and port does syslog use to ship messages to a collector?
Q2. What is the main reason to forward logs to a separate collector instead of keeping them only on the appliance?
© 2026 <ADD AUTHOR / ORG> — clean-room build · N10-007 3.3 · N10-009 3.2 (provisional) · AP NET 4.5.C