[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-09-04。"],[[["\u003cp\u003eThis document explains how to collect Kemp Load Balancer logs using a Google Security Operations forwarder, which supports parsing logs with the \u003ccode\u003eKEMP_LOADBALANCER\u003c/code\u003e ingestion label.\u003c/p\u003e\n"],["\u003cp\u003eTo configure Kemp Load Balancer, you must specify the IP address of the Google Security Operations forwarder in the Syslog options, and then add a new forwarder and collector in SIEM Settings with specific details including protocol, address, and port.\u003c/p\u003e\n"],["\u003cp\u003eThe parser extracts various fields from Kemp Load Balancer syslog messages, based on the log number, mapping them to the UDM, and includes fields such as \u003ccode\u003eprincipal.ip\u003c/code\u003e, \u003ccode\u003etarget.ip\u003c/code\u003e, \u003ccode\u003enetwork.http.method\u003c/code\u003e, and \u003ccode\u003esecurity_result.summary\u003c/code\u003e.\u003c/p\u003e\n"],["\u003cp\u003eThe document provides a detailed UDM mapping table showing how Kemp Load Balancer log fields are mapped to UDM fields, along with the logic used for data conversion and enrichment.\u003c/p\u003e\n"],["\u003cp\u003eRecent updates include improvements to the parsers that now includes events like "connected", "slave accept", and "block access to host", alongside mapping of additional fields like source and destination IPs and ports.\u003c/p\u003e\n"]]],[],null,["# Collect Kemp Load Balancer logs\n===============================\n\nSupported in: \nGoogle secops [SIEM](/chronicle/docs/secops/google-secops-siem-toc)\n| **Note:** This feature is covered by [Pre-GA Offerings Terms](https://chronicle.security/legal/service-terms/) of the Google Security Operations Service Specific Terms. Pre-GA features might have limited support, and changes to pre-GA features might not be compatible with other pre-GA versions. For more information, see the [Google SecOps Technical Support Service guidelines](https://chronicle.security/legal/technical-support-services-guidelines/) and the [Google SecOps Service Specific Terms](https://chronicle.security/legal/service-terms/).\n\nThis document describes how you can collect Kemp Load Balancer logs by using a\nGoogle Security Operations forwarder.\n\nFor more information, see [Data ingestion to Google Security Operations](/chronicle/docs/data-ingestion-flow).\n\nAn ingestion label identifies the parser which normalizes raw log data to structured\nUDM format. The information in this document applies to the parser with the\n`KEMP_LOADBALANCER` ingestion label.\n\nConfigure Kemp Load Balancer\n----------------------------\n\n1. Sign in to the **Kemp Load Balancer** console.\n2. Select **Logging options** \\\u003e **Syslog options**.\n3. In the **Syslog options** section, in any of the available fields specify the\n IP address of the Google Security Operations forwarder.\n\n It is recommended to specify the IP address in the **Info host** field.\n4. Click **Change syslog parameters**.\n\nConfigure Google Security Operations forwarder to ingest Kemp Load Balancer logs\n--------------------------------------------------------------------------------\n\n1. Select **SIEM Settings** \\\u003e **Forwarders**.\n2. Click **Add new forwarder**.\n3. In the **Forwarder name** field, enter a unique name for the forwarder.\n4. Click **Submit** and then click **Confirm** . The forwarder is added and the **Add collector configuration** window appears.\n5. In the **Collector name** field, type a unique name for the collector.\n6. Select **Kemp Load Balancer** as the **Log type**.\n7. Select **Syslog** as the **Collector type**.\n8. Configure the following mandatory input parameters:\n - **Protocol**: specify the connection protocol that the collector uses to listen to syslog data.\n - **Address**: specify the target IP address or hostname where the collector resides and listens to syslog data.\n - **Port**: specify the target port where the collector resides and listens to syslog data.\n9. Click **Submit**.\n\nFor more information about the Google Security Operations forwarders, see [Manage forwarder configurations through the Google Security Operations UI](/chronicle/docs/install/forwarder-management-configurations).\n\nIf you encounter issues when you create forwarders, contact [Google Security Operations support](/chronicle/docs/getting-support).\n\nField mapping reference\n-----------------------\n\nThis parser extracts fields from Kemp Load Balancer syslog messages based on the `log_number` field, mapping them to the UDM. It handles various log formats using `grok` patterns and conditional logic, converting data types and enriching events with metadata like event type, application protocol, and security results.\n\nUDM mapping table\n-----------------\n\n**Need more help?** [Get answers from Community members and Google SecOps professionals.](https://security.googlecloudcommunity.com/google-security-operations-2)"]]