TEAM: Huntress Managed Security Information and Event Management (SIEM)
PRODUCT: SIEM Syslog
ENVIRONMENT: N-able N-central
SUMMARY: Configuration Guide for N-able N-central Syslog Export
In This Article
Overview
Vendor Information
Before You Begin
Configure N-able N-central Syslog Export
Example Log Messages
Overview
This guide explains how to configure device-specific syslog export settings in N-able N-central. To complete the setup, you must also follow the Huntress Managed SIEM Syslog Guide and open the required port in Microsoft Defender Firewall.
Vendor Information
The following table outlines the supported vendor specifications and configuration parameters for N-able N-central audit exports.
| Field | Value |
|---|---|
| Vendor | N-able |
| Supported Model Name/Number | N-central (on-premises) |
| Supported Software Version(s) | Any version with Syslog Export under Administration > Audit Export |
| Collection Method | Syslog |
| Provider Name | Syslog N-central |
| Additional Information | N-central: Configure Syslog Export |
Before You Begin (Important! Don't skip!)
Review the following configuration requirements before setting up your syslog export.
- N-central's TLS option only lets N-central validate the receiving server's certificate, it has no field to present a client certificate of its own. Huntress's encrypted syslog endpoint requires a client certificate, so N-central cannot connect to it. Leave TLS disabled in N-central and use the unencrypted Huntress Agent collector below instead.
- Hosted N-central forces TLS on port 6514 with no way to disable it, so hosted N-central cannot send syslog to Huntress today. Contact Huntress Support if you're on hosted N-central.
Configure N-able N-central Syslog Export
Follow these steps to set up syslog collection for N-able N-central on-premises deployments.
Set up a Huntress Agent as your syslog collector by following the Huntress Managed SIEM Syslog Guide. Make note of its internal IP address and listening port (default
514).In N-able N-central, go to Administration > Audit Export.
In the Syslog Server Hostname/IP Address field, enter the internal IP address (or FQDN) of your Huntress Agent syslog collector.
In the Syslog Server Port field, enter your collector's listening port (default
514).Make sure the Enable TLS setting is turned off.
Turn on the Enable Export toggle, then select Test Export to send a test record.
To confirm that the test record arrived, follow the instructions in the Troubleshooting SIEM Local Syslog Collection guide.
Example Log Messages
Console:
<13>Sep 6 09:38:10 advantage2 <110>1 2026-09-06T09:38:09.779-05:00 - ncentraldms - login.encryptedlogin - [admin@example.com] logged in from 47.210.124.199 logged in at 2026-09-06 09:38:09.779, user customer path in [System]
SSH Audit:
<13>Sep 6 10:15:22 advantage2 <110>1 2026-09-06T10:15:22.000-05:00 - ssh.audit - sshLogin - User [admin] logged in with password from 10.0.0.5 in [advantage2] at 2026-09-06 10:15:21.998
--
Note that Huntress provides third party vendor instructions as a best effort to expedite onboarding. Vendor documentation and versions frequently change and so it may be necessary to find the appropriate documentation for syslog logging for your version of the vendor software or service.