Ship syslog to SIEM
I have been exploring Graylog and its use cases for detecting events on my network. Today I was wondering if SS has a syslog equivalent exposed on some port to which I could have Graylog listen and capture.
I see there is a log.txt in SS that allows me to see camera disconnects and errors. Would be fun to capture that, or a log like it, and build some alerts for certain events.
Comments
SecuritySpy does expose an event stream via its web interface. This is documented under the Miscellaneous section of the Web Server Specification document. I don't know whether this can be digested by Graylog, but perhaps this is something that would be useful for you for this project.