The tag vpn.pulsesecure.sa identifies all log events generated by all the Pulse Secure products.
For information about Pulse Secure, see the vendor technical documentation online.
This technology uses a single tag to receive all the events related to Pulse Secure products. The tag is simply vpn.pulsesecure.sa and the associated events are saved in Devo in a table of the same name.
For more information, read more about Devo tags.
To configure the event sending, you'll set up a relay rule on your Devo Relay that applies the vpn.pulsesecure.sa tag before forwarding the events to Devo in syslog format. In the example below, we use port 514 but you should use any port that you can dedicate to these events.
- Source Port → 514
- Target Tag → vpn.pulsesecure.sa
- Check the Stop processing and Sent without syslog tag checkboxes.
Pulse Secure products can export events in three different formats: Standard, WELF, or Custom. Devo is equipped with parsers for events in Standard and WELF formats. However, if you need to send your data in Custom format, you'll need a custom parser.
See below the event format for the Standard and WELF options: