skip to main text

Sending a Security Log

You can send a log to the SIEM (Security Information and Event Management) system to check/analyze how the printer is being used.

See "Log types" for details on sent logs.

Settings for sending logs are made from the Remote UI.

Important

  • Administrator privileges are required to make settings for sending logs.

  1. Log in to the Remote UI in Administrator Mode.

  2. Select Settings/Registration.

  3. In Management Settings, select Device Management.

  4. Select Syslog Settings.

  5. Select Edit....

    The Edit Syslog Settings screen appears.

  6. Checkmark Use Syslog Send.

  7. Enter the address of the Syslog server to connect to in Syslog Server Address.

    Enter an IP address, host name, etc., according to the requirements of your environment.

  8. Make settings for accessing the Syslog server as required.

    Syslog Server Port Number

    Enter the port number the Syslog server uses for Syslog communication. If left blank, an RFC-designated port number (UDP: 514, TCP: 1468, TCP (TLS): 6514) is set.

    Facility

    Specify the type of log message to send. Select from RFC-designated LPR, Security Messages, Log Audit, Log Alert, and Local0 to Local7.

    Connection Type

    Select UDP or TCP. If you selected TCP, you can also specify whether to use TLS, and verification of the TLS server certificate and its CN (Common Name) sent when connecting.

  9. Select OK.

    Sending of logs is set, and checking of send logs in the Syslog Settings screen becomes possible.

    Note

    • Logs are sent by Syslog Send every 30 seconds after polling. As a result, a time lag occurs somewhat between operation or an event occurring and until a log is sent.

Log types

You can manage the following logs. You can send collected logs by Syslog Send to the SIEM (Security Information and Event Management) system.

Log type Number indicated as "log type" Overview
User authentication log 4098 Log regarding user authentication status (login / logout, authentication success/fail), and registration/change/deletion of user information managed with User Authentication.
Job log 1001 Log regarding completion of copy, scan, send, and print jobs.
Send/receive log 8193 Log regarding sends/receives.
Printer management log 8198 Log regarding printer startup/shutdown, settings changes, etc. Changes made to settings pertaining to user information and security when the printer is being inspected or repaired are also recorded in the printer management log.
Network authentication log 8200 Log having failed IPSec communication recorded.
Security policy log 8204 Log regarding current security policy settings.
System maintenance log 8206 Log regarding firmware updates, etc.